Back

CRITICAL

php variable counter integer overflow

Published Mar 10, 2007

Description

Integer overflow in the 16 bit variable reference counter in PHP 4 allows context-dependent attackers to execute arbitrary code by overflowing this counter, which causes the same variable to be destroyed twice, a related issue to CVE-2007-1286.

Affected products

Remediation

Red Hat statement

The PHP interpreter does not offer a reliable "sandboxed" security layer (as found in, say, a JVM) in which untrusted scripts can be run; any script run by the PHP interpreter must be trusted with the privileges of the interpreter itself. We therefore do not classify this issue as security-sensitive since no trust boundary is crossed.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 10, 2007
Updated Apr 3, 2025
Reserved Mar 9, 2007
CISA Vulnrichment
Updated Apr 3, 2025
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a