php: ext/imap legacy routine buffer overflow
Published Jun 23, 2008
5.0
MEDIUMCVSS 2.0
EPSS 5.27%
Description
php_imap.c in PHP 5.2.5, 5.2.6, 4.x, and other versions, uses obsolete API calls that allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long IMAP request, which triggers an "rfc822.c legacy routine buffer overflow" error message, related to the rfc822_write_address function.
Affected products
No data.
Configuration 1
Configuration 2
- 6.06
- 7.04
- 7.10
- 8.04
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of PHP as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5. For more details see: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-2829
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (23 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 5.27% (0.05265) | 92.30th | v5 (v2026.06.15) |
| Jun 15, 2026 | 5.27% (0.05265) | 91.47th | v5 (v2026.06.15) |
| Dec 28, 2025 | 9.64% (0.09637) | 92.63th | v4 (v2025.03.14) |
| Dec 27, 2025 | 7.16% (0.07159) | 91.30th | v4 (v2025.03.14) |
| Dec 10, 2025 | 9.64% (0.09637) | 92.61th | v4 (v2025.03.14) |
| Oct 30, 2025 | 8.21% (0.08213) | 91.81th | v4 (v2025.03.14) |
| Oct 28, 2025 | 9.64% (0.09637) | 92.53th | v4 (v2025.03.14) |
| Oct 27, 2025 | 7.16% (0.07159) | 91.18th | v4 (v2025.03.14) |
| Oct 16, 2025 | 9.64% (0.09637) | 92.52th | v4 (v2025.03.14) |
| Oct 1, 2025 | 8.21% (0.08213) | 91.92th | v4 (v2025.03.14) |
| Jul 30, 2025 | 7.16% (0.07159) | 91.17th | v4 (v2025.03.14) |
| Jul 7, 2025 | 8.21% (0.08213) | 91.77th | v4 (v2025.03.14) |
| Mar 30, 2025 | 17.69% (0.17690) | 94.57th | v4 (v2025.03.14) |
| Mar 29, 2025 | 22.15% (0.22148) | 93.18th | v4 (v2025.03.14) |
| Mar 19, 2025 | 17.69% (0.17690) | 94.35th | v4 (v2025.03.14) |
| Mar 17, 2025 | 15.79% (0.15795) | 94.23th | v4 (v2025.03.14) |
| Dec 17, 2024 | 13.27% (0.13268) | 95.55th | v3 (v2023.03.01) |
| Dec 12, 2024 | 1.03% (0.01027) | 84.50th | v3 (v2023.03.01) |
| Mar 30, 2024 | 0.99% (0.00987) | 83.18th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.99% (0.00987) | 81.18th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.23% (0.04229) | 87.47th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.23% (0.04229) | 86.19th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.23% (0.04229) | 69.94th | v2 (v2022.01.01) |
References (32)
- http://bugs.php.net/bug.php?id=42862 x_refsource_MISCVendor Advisory
- http://lists.apple.com/archives/security-announce/2009/May/msg00002.html vendor-advisoryx_refsource_APPLEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://marc.info/?l=bugtraq&m=124654546101607&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=125631037611762&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://osvdb.org/46641 vdb-entryx_refsource_OSVDBBroken Link
- http://secunia.com/advisories/31200 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/32746 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/35074 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/35306 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/35650 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://security.gentoo.org/glsa/glsa-200811-05.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://support.apple.com/kb/HT3549 x_refsource_CONFIRMThird Party Advisory
- http://wiki.rpath.com/Advisories:rPSA-2009-0035 x_refsource_CONFIRMBroken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:126 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:127 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:128 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.openwall.com/lists/oss-security/2008/06/19/6 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2008/06/24/2 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.securityfocus.com/archive/1/501376/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/29829 vdb-entryx_refsource_BIDPatchThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/usn-628-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.us-cert.gov/cas/techalerts/TA09-133A.html third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource
- http://www.vupen.com/english/advisories/2009/1297 vdb-entryx_refsource_VUPENPatchThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2008-2829 Vendor Advisory
- https://bugs.gentoo.org/show_bug.cgi?id=221969 x_refsource_CONFIRMThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=452808 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43357 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2008-2829
- https://www.cve.org/CVERecord?id=CVE-2008-2829
- https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01451.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01465.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
Change history (0)
No recorded changes yet.