php crash in glob() and fnmatch() functions
Published Sep 10, 2007
5.0
MEDIUMCVSS 2.0
EPSS 4.70%
Description
PHP before 5.2.3 allows context-dependent attackers to cause a denial of service (application crash) via (1) a long string in the pattern parameter to the glob function; or (2) a long string in the string parameter to the fnmatch function, accompanied by a pattern parameter value with undefined characteristics, as demonstrated by a "*[1]e" value. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless these issues can be demonstrated for code execution.
Affected products
No data.
No data.
Red Hat Enterprise Linux 3
php-0:4.3.2-48.ent
Fixed · RHSA-2008:0544
Red Hat Enterprise Linux 4
php-0:4.3.9-3.22.12
Fixed · RHSA-2008:0545
Red Hat Enterprise Linux 5
php-0:5.1.6-20.el5_2.1
Fixed · RHSA-2008:0544
Red Hat Web Application Stack for RHEL 4
php-0:5.1.6-3.el4s1.10
Fixed · RHSA-2008:0582
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | php-0:4.3.2-48.ent | Fixed | RHSA-2008:0544 |
| Red Hat Enterprise Linux 4 | php-0:4.3.9-3.22.12 | Fixed | RHSA-2008:0545 |
| Red Hat Enterprise Linux 5 | php-0:5.1.6-20.el5_2.1 | Fixed | RHSA-2008:0544 |
| Red Hat Web Application Stack for RHEL 4 | php-0:5.1.6-3.el4s1.10 | Fixed | RHSA-2008:0582 |
No package ranges for this CVE.
Remediation
Red Hat statement
We do not consider this to be a security issue. For more information please see https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=169857#c1 and https://www.php.net/security-note.php
References (27)
- http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00006.html vendor-advisoryx_refsource_SUSE
- http://osvdb.org/38686 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/27102 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/28658 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30828 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/31119 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/31200 third-party-advisoryx_refsource_SECUNIA
- http://securityreason.com/securityalert/3109 third-party-advisoryx_refsource_SREASON
- http://www.gentoo.org/security/en/glsa/glsa-200710-02.xml vendor-advisoryx_refsource_GENTOO
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:022 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:023 vendor-advisoryx_refsource_MANDRIVA
- http://www.redhat.com/support/errata/RHSA-2008-0505.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0544.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0545.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0582.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/478626/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/478630/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/478726/100/0/threaded mailing-listx_refsource_BUGTRAQExploit
- http://www.ubuntu.com/usn/usn-628-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2007-4782 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=285881 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36457 vdb-entryx_refsource_XF
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36461 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2007-4782
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10897 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2007-4782
- https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00773.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.