Off-by-one error in the str_ireplace function in PHP 5.2.1 might allow context-dependent attackers to cause a denial of service (crash).
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-lang/php. | Oct 30, 2017 | Feb 13, 2007 |
| Php | — | Upgrade to PHP version 5.2.2 | Oct 1, 2012 | Feb 13, 2007 |
| Suse | — | Upgrade php4-exifUpgrade php4-develUpgrade php5-domUpgrade php5-wddxUpgrade php5-xmlrpcUpgrade php5-iconvUpgrade php4-sysvshmUpgrade php5-imapUpgrade php4-unixODBCUpgrade php5-mhashUpgrade php4-mysqlUpgrade apache2-mod_php5Upgrade php5-zipUpgrade php5-mbstringUpgrade mod_php4-servletUpgrade php5-ftpUpgrade php4-pearUpgrade php5-exifUpgrade php5-soapUpgrade php5-sysvmsgUpgrade php5-mysqlUpgrade php5-odbcUpgrade php5-develUpgrade apache2-mod_php4Upgrade php5-bcmathUpgrade php5-curlUpgrade php5-ldapUpgrade php4-mhashUpgrade php5-dbaUpgrade apache-mod_php4Upgrade php5-sysvshmUpgrade php4-fastcgiUpgrade php5-gdUpgrade php5-pgsqlUpgrade php5-fastcgiUpgrade php4-wddxUpgrade suse-releaseUpgrade php5-pearUpgrade php4-imapUpgrade mod_php4-coreUpgrade php4-session | Feb 17, 2015 | Feb 13, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub