Back

MEDIUM

php: ext/imap legacy routine buffer overflow

Published Jun 23, 2008

Description

php_imap.c in PHP 5.2.5, 5.2.6, 4.x, and other versions, uses obsolete API calls that allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long IMAP request, which triggers an "rfc822.c legacy routine buffer overflow" error message, related to the rfc822_write_address function.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of PHP as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5. For more details see: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-2829

Metrics

References (32)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 23, 2008
Updated Aug 7, 2024
Reserved Jun 23, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Oct 5, 2007