security flaw
Published Mar 6, 2007
7.5
HIGHCVSS 3.1
EPSS 18.16%
Description
The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.
Affected products
No data.
Configuration 2
- 7.10
Configuration 3
- 10.0
- 10.1
- 8
- 10
Configuration 4
- 3.0
- 4.0
- 2.0
- 3.0
- 4.0
- 2.0
- 3.0
- 4.0
No data.
Red Hat Enterprise Linux 2.1
php-0:4.1.2-2.17
Fixed · RHSA-2007:0154
Red Hat Enterprise Linux 3
php-0:4.3.2-40.ent
Fixed · RHSA-2007:0155
Red Hat Enterprise Linux 4
php-0:4.3.9-3.22.4
Fixed · RHSA-2007:0155
Red Hat Enterprise Linux 5
php-0:5.1.6-7.el5
Fixed · RHSA-2007:0082
Red Hat Web Application Stack for RHEL 4
php-0:5.1.6-3.el4s1.6
Fixed · RHSA-2007:0162
Stronghold 4.0 for RHEL 2.1AS
stronghold-php-0:4.1.2-15
Fixed · RHSA-2007:0163
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 2.1 | php-0:4.1.2-2.17 | Fixed | RHSA-2007:0154 |
| Red Hat Enterprise Linux 3 | php-0:4.3.2-40.ent | Fixed | RHSA-2007:0155 |
| Red Hat Enterprise Linux 4 | php-0:4.3.9-3.22.4 | Fixed | RHSA-2007:0155 |
| Red Hat Enterprise Linux 5 | php-0:5.1.6-7.el5 | Fixed | RHSA-2007:0082 |
| Red Hat Web Application Stack for RHEL 4 | php-0:5.1.6-3.el4s1.6 | Fixed | RHSA-2007:0162 |
| Stronghold 4.0 for RHEL 2.1AS | stronghold-php-0:4.1.2-15 | Fixed | RHSA-2007:0163 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (31 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 18.16% (0.18162) | 97.12th | v5 (v2026.06.15) |
| Jun 15, 2026 | 18.16% (0.18162) | 96.83th | v5 (v2026.06.15) |
| Jun 7, 2026 | 5.68% (0.05679) | 90.57th | v4 (v2025.03.14) |
| Mar 30, 2026 | 6.82% (0.06815) | 91.28th | v4 (v2025.03.14) |
| Dec 28, 2025 | 8.63% (0.08632) | 92.14th | v4 (v2025.03.14) |
| Dec 27, 2025 | 12.38% (0.12378) | 93.70th | v4 (v2025.03.14) |
| Oct 28, 2025 | 8.63% (0.08632) | 92.04th | v4 (v2025.03.14) |
| Oct 27, 2025 | 12.38% (0.12378) | 93.61th | v4 (v2025.03.14) |
| Oct 23, 2025 | 8.63% (0.08632) | 92.02th | v4 (v2025.03.14) |
| Oct 1, 2025 | 6.89% (0.06889) | 91.05th | v4 (v2025.03.14) |
| Jul 30, 2025 | 9.98% (0.09983) | 92.72th | v4 (v2025.03.14) |
| Jul 12, 2025 | 6.89% (0.06889) | 90.94th | v4 (v2025.03.14) |
| May 15, 2025 | 8.07% (0.08072) | 91.66th | v4 (v2025.03.14) |
| Apr 15, 2025 | 11.46% (0.11458) | 93.14th | v4 (v2025.03.14) |
| Mar 31, 2025 | 12.67% (0.12665) | 93.36th | v4 (v2025.03.14) |
| Mar 30, 2025 | 13.94% (0.13940) | 93.72th | v4 (v2025.03.14) |
| Mar 29, 2025 | 16.44% (0.16438) | 91.50th | v4 (v2025.03.14) |
| Mar 19, 2025 | 13.94% (0.13940) | 93.49th | v4 (v2025.03.14) |
| Mar 17, 2025 | 16.94% (0.16936) | 94.47th | v4 (v2025.03.14) |
| Dec 17, 2024 | 21.20% (0.21198) | 96.41th | v3 (v2023.03.01) |
| Nov 9, 2024 | 15.93% (0.15932) | 96.09th | v3 (v2023.03.01) |
| Jul 29, 2024 | 13.26% (0.13263) | 95.62th | v3 (v2023.03.01) |
| Jun 9, 2024 | 10.14% (0.10144) | 94.95th | v3 (v2023.03.01) |
| Feb 3, 2024 | 11.25% (0.11248) | 94.71th | v3 (v2023.03.01) |
| Jan 8, 2024 | 28.30% (0.28299) | 96.39th | v3 (v2023.03.01) |
| Dec 1, 2023 | 11.10% (0.11099) | 94.56th | v3 (v2023.03.01) |
| Oct 24, 2023 | 20.16% (0.20165) | 95.76th | v3 (v2023.03.01) |
| Mar 7, 2023 | 20.52% (0.20518) | 95.56th | v3 (v2023.03.01) |
| Mar 6, 2023 | 15.27% (0.15272) | 95.95th | v2 (v2022.01.01) |
| Apr 1, 2022 | 15.27% (0.15272) | 95.58th | v2 (v2022.01.01) |
| Feb 4, 2022 | 15.27% (0.15272) | 91.38th | v2 (v2022.01.01) |
References (42)
- http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html vendor-advisoryx_refsource_SUSEMailing List
- http://rhn.redhat.com/errata/RHSA-2007-0154.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2007-0155.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2007-0163.html vendor-advisoryx_refsource_REDHATBroken Link
- http://secunia.com/advisories/24909 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/24910 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/24924 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/24941 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/24945 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/25445 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/26048 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/26642 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/27864 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/28936 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://security.gentoo.org/glsa/glsa-200705-19.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.335136 vendor-advisoryx_refsource_SLACKWAREBroken Link
- http://us2.php.net/releases/4_4_7.php x_refsource_CONFIRMRelease Notes
- http://us2.php.net/releases/5_2_2.php x_refsource_CONFIRMRelease Notes
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:087 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:088 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:089 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:090 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.osvdb.org/32769 vdb-entryx_refsource_OSVDBBroken Link
- http://www.php-security.org/MOPB/MOPB-03-2007.html x_refsource_MISCBroken LinkExploitVendor Advisory
- http://www.php.net/ChangeLog-4.php x_refsource_CONFIRMRelease Notes
- http://www.php.net/ChangeLog-5.php#5.2.4 x_refsource_CONFIRMRelease Notes
- http://www.php.net/releases/4_4_8.php x_refsource_CONFIRMRelease Notes
- http://www.php.net/releases/5_2_4.php x_refsource_CONFIRMRelease Notes
- http://www.redhat.com/support/errata/RHSA-2007-0082.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.redhat.com/support/errata/RHSA-2007-0162.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.securityfocus.com/archive/1/466166/100/0/threaded mailing-listx_refsource_BUGTRAQBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/22764 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1017771 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/usn-549-2 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2007-1285 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1618296 Issue Tracking
- https://issues.rpath.com/browse/RPL-1268 x_refsource_CONFIRMBroken Link
- https://launchpad.net/bugs/173043 x_refsource_CONFIRMExploitIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2007-1285
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11017 vdb-entrysignaturex_refsource_OVALBroken Link
- https://usn.ubuntu.com/549-1/ vendor-advisoryx_refsource_UBUNTUBroken Link
- https://www.cve.org/CVERecord?id=CVE-2007-1285
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html | vendor-advisoryx_refsource_SUSEMailing List | |
| http://rhn.redhat.com/errata/RHSA-2007-0154.html | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| http://rhn.redhat.com/errata/RHSA-2007-0155.html | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| http://rhn.redhat.com/errata/RHSA-2007-0163.html | vendor-advisoryx_refsource_REDHATBroken Link | |
| http://secunia.com/advisories/24909 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/24910 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/24924 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/24941 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/24945 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/25445 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/26048 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/26642 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/27864 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/28936 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://security.gentoo.org/glsa/glsa-200705-19.xml | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.335136 | vendor-advisoryx_refsource_SLACKWAREBroken Link | |
| http://us2.php.net/releases/4_4_7.php | x_refsource_CONFIRMRelease Notes | |
| http://us2.php.net/releases/5_2_2.php | x_refsource_CONFIRMRelease Notes | |
| http://www.mandriva.com/security/advisories?name=MDKSA-2007:087 | vendor-advisoryx_refsource_MANDRIVAThird Party Advisory | |
| http://www.mandriva.com/security/advisories?name=MDKSA-2007:088 | vendor-advisoryx_refsource_MANDRIVAThird Party Advisory | |
| http://www.mandriva.com/security/advisories?name=MDKSA-2007:089 | vendor-advisoryx_refsource_MANDRIVAThird Party Advisory | |
| http://www.mandriva.com/security/advisories?name=MDKSA-2007:090 | vendor-advisoryx_refsource_MANDRIVAThird Party Advisory | |
| http://www.osvdb.org/32769 | vdb-entryx_refsource_OSVDBBroken Link | |
| http://www.php-security.org/MOPB/MOPB-03-2007.html | x_refsource_MISCBroken LinkExploitVendor Advisory | |
| http://www.php.net/ChangeLog-4.php | x_refsource_CONFIRMRelease Notes | |
| http://www.php.net/ChangeLog-5.php#5.2.4 | x_refsource_CONFIRMRelease Notes | |
| http://www.php.net/releases/4_4_8.php | x_refsource_CONFIRMRelease Notes | |
| http://www.php.net/releases/5_2_4.php | x_refsource_CONFIRMRelease Notes | |
| http://www.redhat.com/support/errata/RHSA-2007-0082.html | vendor-advisoryx_refsource_REDHATBroken Link | |
| http://www.redhat.com/support/errata/RHSA-2007-0162.html | vendor-advisoryx_refsource_REDHATBroken Link | |
| http://www.securityfocus.com/archive/1/466166/100/0/threaded | mailing-listx_refsource_BUGTRAQBroken LinkThird Party AdvisoryVDB Entry | |
| http://www.securityfocus.com/bid/22764 | vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id?1017771 | vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry | |
| http://www.ubuntu.com/usn/usn-549-2 | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2007-1285 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1618296 | Issue Tracking | |
| https://issues.rpath.com/browse/RPL-1268 | x_refsource_CONFIRMBroken Link | |
| https://launchpad.net/bugs/173043 | x_refsource_CONFIRMExploitIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2007-1285 | ||
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11017 | vdb-entrysignaturex_refsource_OVALBroken Link | |
| https://usn.ubuntu.com/549-1/ | vendor-advisoryx_refsource_UBUNTUBroken Link | |
| https://www.cve.org/CVERecord?id=CVE-2007-1285 |
Change history (0)
No recorded changes yet.