CVE Database
/

CVE-2007-4782

Back to search

CVE-2007-4782

Published: Sep 10, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

PHP before 5.2.3 allows context-dependent attackers to cause a denial of service (application crash) via (1) a long string in the pattern parameter to the glob function; or (2) a long string in the string parameter to the fnmatch function, accompanied by a pattern parameter value with undefined characteristics, as demonstrated by a "*[1]e" value. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless these issues can be demonstrated for code execution.

VendorProductVersions

n/a

n/a

affected
n/a

References

FEDORA-2008-3864
vendor-advisory
x_refsource_FEDORA
SUSE-SA:2008:004
vendor-advisory
x_refsource_SUSE
28658
third-party-advisory
x_refsource_SECUNIA
30828
third-party-advisory
x_refsource_SECUNIA
RHSA-2008:0582
vendor-advisory
x_refsource_REDHAT
GLSA-200710-02
vendor-advisory
x_refsource_GENTOO
USN-628-1
vendor-advisory
x_refsource_UBUNTU
20070904 PHP < 5.2.3 glob() denial of service
mailing-list
x_refsource_BUGTRAQ
RHSA-2008:0545
vendor-advisory
x_refsource_REDHAT
31119
third-party-advisory
x_refsource_SECUNIA
MDVSA-2009:023
vendor-advisory
x_refsource_MANDRIVA
MDVSA-2009:022
vendor-advisory
x_refsource_MANDRIVA
php-fnmatch-dos(36457)
vdb-entry
x_refsource_XF
31200
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:10897
vdb-entry
signature
x_refsource_OVAL
RHSA-2008:0544
vendor-advisory
x_refsource_REDHAT
38686
vdb-entry
x_refsource_OSVDB
php-globfunction-dos(36461)
vdb-entry
x_refsource_XF
27102
third-party-advisory
x_refsource_SECUNIA
RHSA-2008:0505
vendor-advisory
x_refsource_REDHAT
3109
third-party-advisory
x_refsource_SREASON
20070905 PHP < 5.2.3 glob() denial of service
mailing-list
x_refsource_BUGTRAQ

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now