Vulnerabilities > CVE-2007-1401 - Local Security vulnerability in PHP 4.4.6

047910
CVSS 6.9 - MEDIUM
Attack vector
LOCAL
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
php
exploit available

Summary

Buffer overflow in the crack extension (CrackLib), as bundled with PHP 4.4.6 and other versions before 5.0.0, might allow local users to gain privileges via a long argument to the crack_opendict function.

Vulnerable Configurations

Part Description Count
Application
Php
1

Exploit-Db

descriptionPHP 4.4.6 crack_opendict() Local Buffer Overflow Exploit PoC. CVE-2007-1401. Local exploit for windows platform
fileexploits/windows/local/3431.php
idEDB-ID:3431
last seen2016-01-31
modified2007-03-08
platformwindows
port
published2007-03-08
reporterrgod
sourcehttps://www.exploit-db.com/download/3431/
titlePHP 4.4.6 crack_opendict Local Buffer Overflow Exploit PoC
typelocal

Statements

contributorMark J Cox
lastmodified2007-03-19
organizationRed Hat
statementNot vulnerable. PHP as shipped with Red Hat Enterprise Linux 2.1, 3, 4, and 5 does not include Cracklib support.