Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to obtain sensitive information (memory contents) or cause a denial of service (thread crash) via a large len value to the (1) strspn or (2) strcspn function, which triggers an out-of-bounds read. NOTE: this affects different product versions than CVE-2007-3996.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade php5Upgrade php4 | Dec 10, 2025 | Sep 11, 2007 |
| Gentoo Linux | — | Upgrade dev-lang/php. | Oct 30, 2017 | Sep 4, 2007 |
| Php | — | Upgrade to PHP version 5.2.4Upgrade to PHP version 4.4.8 | Oct 1, 2012 | Sep 4, 2007 |
| Ubuntu | — | Upgrade libapache2-mod-php5Upgrade php5-cgiUpgrade php5-cli | Nov 8, 2024 | Sep 4, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub