Multiple heap-based buffer overflows in the (1) str_repeat and (2) wordwrap functions in ext/standard/string.c in PHP before 5.1.5, when used on a 64-bit system, have unspecified impact and attack vectors, a different vulnerability than CVE-2006-1990.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade php4Upgrade php5Upgrade php4-nmsUpgrade mod_php4Upgrade php4-cgiUpgrade php5-cgiUpgrade php5-dtcUpgrade php4-cliUpgrade php4-hordeUpgrade mod_php5Upgrade php5-nmsUpgrade php5-hordeUpgrade php5-cliUpgrade php4-dtc | Dec 10, 2025 | Sep 13, 2006 |
| Php | — | Upgrade to PHP version 5.1.5 | Oct 1, 2012 | Aug 31, 2006 |
| Ubuntu | — | Upgrade libapache2-mod-php5Upgrade php5-cliUpgrade php5-cgiUpgrade libapache2-mod-php4Upgrade php4-cgiUpgrade php4-cliUpgrade php5-curl | Nov 8, 2024 | Aug 31, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub