Vulnerabilities > CVE-2007-1411 - Local Buffer Overflow vulnerability in PHP MSSQL_Connect

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
php

Summary

Buffer overflow in PHP 4.4.6 and earlier, and unspecified PHP 5 versions, allows local and possibly remote attackers to execute arbitrary code via long server name arguments to the (1) mssql_connect and (2) mssql_pconnect functions.

Vulnerable Configurations

Part Description Count
Application
Php
243

Statements

contributorMark J Cox
lastmodified2007-03-19
organizationRed Hat
statementNot vulnerable. PHP as shipped with Red Hat Enterprise Linux 2.1, 3, 4, and 5 does not include mssql support.