Back

HIGH

Off-by-one error in the str_ireplace function in PHP 5.2.1 might allow context-dependent attackers to cause a denial of service (crash)

Published Feb 13, 2007

Description

Off-by-one error in the str_ireplace function in PHP 5.2.1 might allow context-dependent attackers to cause a denial of service (crash).

Affected products

Remediation

Red Hat statement

Not vulnerable. This flaw is a regression of the fix for CVE-2007-0906 affecting PHP version 5.2.1 only which results in any use of str_replace() causing a crash regardless of user input. These issues did not affect the versions of PHP as shipped with Red Hat Enterprise Linux 2.1, 3, or 4.

Metrics

Weaknesses (0)

No CWE recorded.

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 13, 2007
Updated Aug 7, 2024
Reserved Feb 13, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a