PublicDate: 2007-09-04 22:17:00 UTC Candidate: CVE-2007-4658 References: https://ubuntu.com/security/notices/USN-549-1 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4658 Description: The money_format function in PHP 5 before 5.2.4, and PHP 4 before 4.4.8, permits multiple (1) %i and (2) %n tokens, which has unknown impact and attack vectors, possibly related to a format string vulnerability. Ubuntu-Description: Notes: kees> from Line 7667, http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/string.c?r1=1.640&r2=1.641 kees> 202-money-format-abuse.patch Bugs: Priority: medium Discovered-by: Assigned-to: kees CVSS: upstream_php5: released (5.2.4) dapper_php5: released (5.1.2-1ubuntu3.10) edgy_php5: released (5.1.6-1ubuntu2.7) feisty_php5: released (5.2.1-0ubuntu1.5) gutsy_php5: released (5.2.3-1ubuntu6.1) devel_php5: not-affected (5.2.4-2ubuntu3)