Back

HIGH

php user_filter_factory_create overflow

Published May 9, 2007

Description

Buffer overflow in the user_filter_factory_create function in PHP before 5.2.2 has unknown impact and local attack vectors.

Affected products

Remediation

Red Hat statement

The PHP interpreter does not offer a reliable "sandboxed" security layer (as found in, say, a JVM) in which untrusted scripts can be run any script run by the PHP interpreter must be trusted with the privileges of the interpreter itself. This bug described in CVE-2007-2511 can only be triggered by a script author since no trust boundary is crossed, this issue is not treated as security-sensitive.

Metrics

Weaknesses (0)

No CWE recorded.

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 9, 2007
Updated Aug 7, 2024
Reserved May 7, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date May 3, 2007