Vulnerabilities > CVE-2007-1584 - Remote Security vulnerability in PHP 5.2.0

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
php
nessus
exploit available

Summary

Buffer underflow in the header function in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by passing an all-whitespace string to this function, which causes it to write '\0' characters in whitespace that precedes the string.

Vulnerable Configurations

Part Description Count
Application
Php
1

Exploit-Db

  • descriptionPHP 5.2.0 ext/filter Space Trimming Buffer Underflow Exploit (MacOSX). CVE-2007-1584. Local exploit for osx platform
    idEDB-ID:3460
    last seen2016-01-31
    modified2007-03-12
    published2007-03-12
    reporterStefan Esser
    sourcehttps://www.exploit-db.com/download/3460/
    titlePHP 5.2.0 ext/filter Space Trimming Buffer Underflow Exploit MacOSX
  • descriptionPHP 5.2.0 header() Space Trimming Buffer Underflow Exploit (MacOSX). CVE-2007-1584. Local exploit for osx platform
    fileexploits/osx/local/3517.php
    idEDB-ID:3517
    last seen2016-01-31
    modified2007-03-19
    platformosx
    port
    published2007-03-19
    reporterStefan Esser
    sourcehttps://www.exploit-db.com/download/3517/
    titlePHP 5.2.0 header Space Trimming Buffer Underflow Exploit MacOSX
    typelocal

Nessus

NASL familyCGI abuses
NASL idPHP_5_2_0.NASL
descriptionAccording to its banner, the version of PHP 5.x installed on the remote host is older than 5.2. Such versions may be affected by several buffer overflows. To exploit these issues, an attacker would need the ability to upload an arbitrary PHP script on the remote server or to manipulate several variables processed by some PHP functions such as
last seen2020-06-01
modified2020-06-02
plugin id31649
published2008-03-25
reporterThis script is Copyright (C) 2008-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/31649
titlePHP 5.x < 5.2 Multiple Vulnerabilities

Statements

contributorMark J Cox
lastmodified2007-05-01
organizationRed Hat
statementThis CVE name is a duplicate as the vulnerability is addressed by CVE-2007-0907.