Executive Summary

Informations
NameCVE-2007-1285First vendor Publication2007-03-06
VendorCveLast vendor Modification2010-11-30

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Cvss Base Score5Attack RangeNetwork
Cvss Impact Score2.9Attack ComplexityLow
Cvss Expoit Score10AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1285

CAPEC : Common Attack Pattern Enumeration & Classification

idName
CAPEC-82Violating Implicit Assumptions Regarding XML Content (aka XML Denial of Servi...
CAPEC-99XML Parser Attack

CWE : Common Weakness Enumeration

idName
CWE-674Uncontrolled Recursion
CWE-119Failure to Constrain Operations within the Bounds of a Memory Buffer

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:11017
 
Oval ID: oval:org.mitre.oval:def:11017
Title: The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.
Description: The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.
Family: unix Class: vulnerability
Reference(s): CVE-2007-1285
Version: 5
Platform(s): Red Hat Enterprise Linux 3
CentOS Linux 3
Red Hat Enterprise Linux 4
CentOS Linux 4
Oracle Linux 4
Red Hat Enterprise Linux 5
CentOS Linux 5
Oracle Linux 5
Product(s):
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application57
Application1

Open Source Vulnerability Database (OSVDB)

idDescription
32769PHP Zend Engine Variable Destruction Deep Recursion Overflow

Internal Sources (Detail)

SourceUrl
BIDhttp://www.securityfocus.com/bid/22764
BUGTRAQhttp://www.securityfocus.com/archive/1/archive/1/466166/100/0/threaded
CONFIRMhttp://us2.php.net/releases/4_4_7.php
http://us2.php.net/releases/5_2_2.php
http://www.php.net/ChangeLog-4.php
http://www.php.net/ChangeLog-5.php#5.2.4
http://www.php.net/releases/4_4_8.php
http://www.php.net/releases/5_2_4.php
https://issues.rpath.com/browse/RPL-1268
https://launchpad.net/bugs/173043
GENTOOhttp://security.gentoo.org/glsa/glsa-200705-19.xml
MANDRIVAhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:087
http://www.mandriva.com/security/advisories?name=MDKSA-2007:088
http://www.mandriva.com/security/advisories?name=MDKSA-2007:089
http://www.mandriva.com/security/advisories?name=MDKSA-2007:090
MISChttp://www.php-security.org/MOPB/MOPB-03-2007.html
OSVDBhttp://www.osvdb.org/32769
REDHAThttp://rhn.redhat.com/errata/RHSA-2007-0154.html
http://rhn.redhat.com/errata/RHSA-2007-0155.html
http://rhn.redhat.com/errata/RHSA-2007-0163.html
http://www.redhat.com/support/errata/RHSA-2007-0082.html
http://www.redhat.com/support/errata/RHSA-2007-0162.html
SECTRACKhttp://www.securitytracker.com/id?1017771
SECUNIAhttp://secunia.com/advisories/24909
http://secunia.com/advisories/24910
http://secunia.com/advisories/24924
http://secunia.com/advisories/24941
http://secunia.com/advisories/24945
http://secunia.com/advisories/25445
http://secunia.com/advisories/26048
http://secunia.com/advisories/26642
http://secunia.com/advisories/27864
http://secunia.com/advisories/28936
SLACKWAREhttp://slackware.com/security/viewer.php?l=slackware-security&y=2008&...
SUSEhttp://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html
UBUNTUhttp://www.ubuntu.com/usn/usn-549-2
http://www.ubuntulinux.org/support/documentation/usn/usn-549-1

Alert History

If you want to see full details history, please login or register.
0
DateInformations
2013-05-11 10:20:16
  • Multiple Updates