Executive Summary
| Informations | |||
|---|---|---|---|
| Name | CVE-2007-1285 | First vendor Publication | 2007-03-06 |
| Vendor | Cve | Last vendor Modification | 2010-11-30 |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:P) | |||
|---|---|---|---|
| Cvss Base Score | 5 | Attack Range | Network |
| Cvss Impact Score | 2.9 | Attack Complexity | Low |
| Cvss Expoit Score | 10 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines. |
Original Source
| Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1285 |
CAPEC : Common Attack Pattern Enumeration & Classification
| id | Name |
|---|---|
| CAPEC-82 | Violating Implicit Assumptions Regarding XML Content (aka XML Denial of Servi... |
| CAPEC-99 | XML Parser Attack |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-674 | Uncontrolled Recursion |
| CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
OVAL Definitions
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 32769 | PHP Zend Engine Variable Destruction Deep Recursion Overflow |
Internal Sources (Detail)
Alert History
| Date | Informations |
|---|---|
| 2013-05-11 10:20:16 |
|

CVE-2007-1285
(Critical)
(High)
(Medium)








