Integer overflow in memory allocation routines in PHP before 5.1.6, when running on a 64-bit system, allows context-dependent attackers to bypass the memory_limit restriction.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade mod_php4Upgrade mod_php5Upgrade php4-cgiUpgrade php5Upgrade php5-cliUpgrade php4Upgrade php5-hordeUpgrade php5-cgiUpgrade php4-hordeUpgrade php5-dtcUpgrade php4-nmsUpgrade php4-cliUpgrade php5-nmsUpgrade php4-dtc | Dec 10, 2025 | Sep 13, 2006 |
| Php | — | Upgrade to PHP version 5.1.6 | Oct 1, 2012 | Aug 31, 2006 |
| Ubuntu | — | Upgrade php4-cgiUpgrade libapache2-mod-php4Upgrade php5-cgiUpgrade libapache2-mod-php5Upgrade php5-cliUpgrade php4-cli | Nov 8, 2024 | Aug 31, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub