PublicDate: 2007-09-04 22:17:00 UTC Candidate: CVE-2007-4662 References: https://ubuntu.com/security/notices/USN-549-1 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4662 Description: Buffer overflow in the php_openssl_make_REQ function in PHP before 5.2.4 has unknown impact and attack vectors. Ubuntu-Description: Notes: kees> http://cvs.php.net/viewcvs.cgi/php-src/ext/openssl/openssl.c?r1=1.146&r2=1.147 kees> upstream is wrong: should be 199 not 200. kees> 203-openssl_make_REQ-overflow.patch Bugs: Priority: medium Discovered-by: Assigned-to: kees CVSS: upstream_php5: released (5.2.4) dapper_php5: released (5.1.2-1ubuntu3.10) edgy_php5: released (5.1.6-1ubuntu2.7) feisty_php5: released (5.2.1-0ubuntu1.5) gutsy_php5: released (5.2.3-1ubuntu6.1) devel_php5: not-affected (5.2.4-2ubuntu3)