MEDIUM
security flaw
Published Mar 27, 2007
6.8
MEDIUMCVSS 2.0
EPSS 7.63%
Description
Double free vulnerability in the unserializer in PHP 4.4.5 and 4.4.6 allows context-dependent attackers to execute arbitrary code by overwriting variables pointing to (1) the GLOBALS array or (2) the session data in _SESSION. NOTE: this issue was introduced when attempting to patch CVE-2007-1701 (MOPB-31-2007).
Affected products
No data.
No data.
Red Hat Enterprise Linux 2.1
php-0:4.1.2-2.17
Fixed · RHSA-2007:0154
Red Hat Enterprise Linux 3
php-0:4.3.2-40.ent
Fixed · RHSA-2007:0155
Red Hat Enterprise Linux 4
php-0:4.3.9-3.22.4
Fixed · RHSA-2007:0155
Stronghold 4.0 for RHEL 2.1AS
stronghold-php-0:4.1.2-15
Fixed · RHSA-2007:0163
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 2.1 | php-0:4.1.2-2.17 | Fixed | RHSA-2007:0154 |
| Red Hat Enterprise Linux 3 | php-0:4.3.2-40.ent | Fixed | RHSA-2007:0155 |
| Red Hat Enterprise Linux 4 | php-0:4.3.9-3.22.4 | Fixed | RHSA-2007:0155 |
| Stronghold 4.0 for RHEL 2.1AS | stronghold-php-0:4.1.2-15 | Fixed | RHSA-2007:0163 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (31)
- http://docs.info.apple.com/article.html?artnum=306172 x_refsource_CONFIRM
- http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html vendor-advisoryx_refsource_APPLE
- http://rhn.redhat.com/errata/RHSA-2007-0154.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2007-0155.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2007-0163.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/24910 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/24924 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/24941 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/24945 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25025 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25062 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25445 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/26235 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200705-19.xml vendor-advisoryx_refsource_GENTOO
- http://www.debian.org/security/2007/dsa-1282 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2007/dsa-1283 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:087 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:088 vendor-advisoryx_refsource_MANDRIVA
- http://www.php-security.org/MOPB/MOPB-32-2007.html x_refsource_MISC
- http://www.securityfocus.com/archive/1/466166/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/23121 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/25159 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2007/2732 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2007-1711 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1618304 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2007-1705 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33575 vdb-entryx_refsource_XF
- https://issues.rpath.com/browse/RPL-1268 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2007-1711
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10406 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2007-1711
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 27, 2007
Updated Aug 7, 2024
Reserved Mar 26, 2007
Link CVE-2007-1711
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2007-1705 Assigner mitre
Published Mar 27, 2007
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2007-1705