PublicDateAtUSN: 2007-09-04 PublicDate: 2007-09-04 22:17:00 UTC Candidate: CVE-2007-4657 References: https://ubuntu.com/security/notices/USN-549-1 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4657 Description: Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to obtain sensitive information (memory contents) or cause a denial of service (thread crash) via a large len value to the (1) strspn or (2) strcspn function, which triggers an out-of-bounds read. NOTE: this affects different product versions than CVE-2007-3996. Ubuntu-Description: Notes: kees> http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/string.c?r1=1.640&r2=1.641, prior to line 7667 kees> 201-strspn-oob-read.patch Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: upstream_php5: released (5.2.4) dapper_php5: released (5.1.2-1ubuntu3.10) edgy_php5: released (5.1.6-1ubuntu2.7) feisty_php5: released (5.2.1-0ubuntu1.5) gutsy_php5: released (5.2.3-1ubuntu6.1) hardy_php5: not-affected (5.2.4-2ubuntu3) intrepid_php5: not-affected (5.2.4-2ubuntu3) jaunty_php5: not-affected (5.2.4-2ubuntu3) karmic_php5: not-affected (5.2.4-2ubuntu3) devel_php5: not-affected (5.2.4-2ubuntu3) Patches_php4: upstream: http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/string.c?r1=1.640&r2=1.641, prior to line 7667 other: 201-strspn-oob-read.patch upstream_php4: released (4.4.8) dapper_php4: ignored (reached end-of-life) edgy_php4: needed (reached end-of-life) feisty_php4: DNE gutsy_php4: DNE hardy_php4: DNE intrepid_php4: DNE jaunty_php4: DNE karmic_php4: DNE devel_php4: DNE