php session extension information leak
Published Mar 10, 2007
5.0
MEDIUMCVSS 2.0
EPSS 9.08%
Description
The php_binary serialization handler in the session extension in PHP before 4.4.5, and 5.x before 5.2.1, allows context-dependent attackers to obtain sensitive information (memory contents) via a serialized variable entry with a large length value, which triggers a buffer over-read.
Affected products
No data.
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0.0
- 4.0.1
- 4.0.1
- 4.0.1
- 4.0.2
- 4.0.3
- 4.0.3
- 4.0.4
- 4.0.4
- 4.0.5
- 4.0.6
- 4.0.7
- 4.0.7
- 4.0.7
- 4.0.7
- 4.1.0
- 4.1.1
- 4.1.2
- 4.2
- 4.2.0
- 4.2.1
- 4.2.2
- 4.2.3
- 4.3.0
- 4.3.1
- 4.3.2
- 4.3.3
- 4.3.4
- 4.3.5
- 4.3.6
- 4.3.7
- 4.3.8
- 4.3.9
- 4.3.10
- 4.3.11
- 4.4.0
- 4.4.1
- 4.4.2
- 4.4.3
- 4.4.4
- 5.0
- 5.0
- 5.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.1
- 5.0.2
- 5.0.3
- 5.0.4
- 5.0.5
- 5.1.0
- 5.1.1
- 5.1.2
- 5.1.3
- 5.1.4
- 5.1.5
- 5.1.6
- 5.2.0
No data.
Red Hat Enterprise Linux 2.1
php-0:4.1.2-2.14
Fixed · RHSA-2007:0081
Red Hat Enterprise Linux 3
php-0:4.3.2-39.ent
Fixed · RHSA-2007:0076
Red Hat Enterprise Linux 4
php-0:4.3.9-3.22.3
Fixed · RHSA-2007:0076
Red Hat Enterprise Linux 5
php-0:5.1.6-7.el5
Fixed · RHSA-2007:0082
Red Hat Web Application Stack for RHEL 4
php-0:5.1.6-3.el4s1.5
Fixed · RHSA-2007:0088
Stronghold 4.0 for RHEL 2.1AS
stronghold-php-0:4.1.2-12
Fixed · RHSA-2007:0089
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 2.1 | php-0:4.1.2-2.14 | Fixed | RHSA-2007:0081 |
| Red Hat Enterprise Linux 3 | php-0:4.3.2-39.ent | Fixed | RHSA-2007:0076 |
| Red Hat Enterprise Linux 4 | php-0:4.3.9-3.22.3 | Fixed | RHSA-2007:0076 |
| Red Hat Enterprise Linux 5 | php-0:5.1.6-7.el5 | Fixed | RHSA-2007:0082 |
| Red Hat Web Application Stack for RHEL 4 | php-0:5.1.6-3.el4s1.5 | Fixed | RHSA-2007:0088 |
| Stronghold 4.0 for RHEL 2.1AS | stronghold-php-0:4.1.2-12 | Fixed | RHSA-2007:0089 |
No package ranges for this CVE.
Remediation
Red Hat statement
Our previous fixes for CVE-2007-0906 included a patch that also addressed the issue now given CVE name CVE-2007-1380.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (27 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 9.08% (0.09082) | 95.15th | v5 (v2026.06.15) |
| Jun 15, 2026 | 9.08% (0.09082) | 94.62th | v5 (v2026.06.15) |
| Feb 10, 2026 | 14.20% (0.14197) | 94.21th | v4 (v2025.03.14) |
| Dec 28, 2025 | 12.71% (0.12708) | 93.75th | v4 (v2025.03.14) |
| Dec 27, 2025 | 10.25% (0.10251) | 92.94th | v4 (v2025.03.14) |
| Oct 28, 2025 | 12.71% (0.12708) | 93.67th | v4 (v2025.03.14) |
| Oct 27, 2025 | 10.25% (0.10251) | 92.83th | v4 (v2025.03.14) |
| Oct 1, 2025 | 14.10% (0.14098) | 94.15th | v4 (v2025.03.14) |
| Jul 30, 2025 | 11.42% (0.11417) | 93.29th | v4 (v2025.03.14) |
| Jul 16, 2025 | 14.10% (0.14098) | 94.03th | v4 (v2025.03.14) |
| Mar 30, 2025 | 11.73% (0.11730) | 93.05th | v4 (v2025.03.14) |
| Mar 29, 2025 | 14.42% (0.14420) | 90.73th | v4 (v2025.03.14) |
| Mar 17, 2025 | 11.73% (0.11730) | 93.14th | v4 (v2025.03.14) |
| Dec 12, 2024 | 1.59% (0.01593) | 87.88th | v3 (v2023.03.01) |
| Feb 19, 2024 | 1.78% (0.01783) | 87.66th | v3 (v2023.03.01) |
| Jan 11, 2024 | 1.99% (0.01989) | 87.58th | v3 (v2023.03.01) |
| Dec 4, 2023 | 1.13% (0.01126) | 82.94th | v3 (v2023.03.01) |
| Oct 27, 2023 | 1.12% (0.01118) | 82.97th | v3 (v2023.03.01) |
| Sep 19, 2023 | 1.14% (0.01144) | 83.07th | v3 (v2023.03.01) |
| Aug 11, 2023 | 1.16% (0.01163) | 83.11th | v3 (v2023.03.01) |
| Jul 4, 2023 | 1.09% (0.01091) | 82.35th | v3 (v2023.03.01) |
| May 29, 2023 | 1.03% (0.01033) | 81.72th | v3 (v2023.03.01) |
| Apr 21, 2023 | 1.06% (0.01065) | 82.03th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.87% (0.00869) | 79.86th | v3 (v2023.03.01) |
| Mar 6, 2023 | 12.57% (0.12567) | 95.52th | v2 (v2022.01.01) |
| Apr 1, 2022 | 12.57% (0.12567) | 95.18th | v2 (v2022.01.01) |
| Feb 4, 2022 | 12.57% (0.12567) | 90.03th | v2 (v2022.01.01) |
No CWE recorded.
References (26)
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01056506 vendor-advisoryx_refsource_HP
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01086137 vendor-advisoryx_refsource_HP
- http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/24514 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/24606 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25025 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25056 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25057 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25062 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25423 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25850 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200703-21.xml vendor-advisoryx_refsource_GENTOO
- http://www.debian.org/security/2007/dsa-1282 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2007/dsa-1283 vendor-advisoryx_refsource_DEBIAN
- http://www.novell.com/linux/security/advisories/2007_32_php.html vendor-advisoryx_refsource_SUSE
- http://www.php-security.org/MOPB/MOPB-10-2007.html x_refsource_MISCExploit
- http://www.securityfocus.com/bid/22805 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/usn-455-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2007/1991 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/2374 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2007-1380 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=240157 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2007-1380
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10792 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2007-1380
- https://www.exploit-db.com/exploits/3413 exploitx_refsource_EXPLOIT-DB
Change history (0)
No recorded changes yet.