CVE Vulnerabilities

CVE-2006-1990

Published: Apr 24, 2006 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Integer overflow in the wordwrap function in string.c in PHP 4.4.2 and 5.1.2 might allow context-dependent attackers to execute arbitrary code via certain long arguments that cause a small buffer to be allocated, which triggers a heap-based buffer overflow in a memcpy function call, a different vulnerability than CVE-2002-1396.

Affected Software

Name Vendor Start Version End Version
Php Php 4.4.2 (including) 4.4.2 (including)
Php Php 5.1.2 (including) 5.1.2 (including)
Red Hat Enterprise Linux 3 RedHat php-0:4.3.2-33.ent *
Red Hat Enterprise Linux 4 RedHat php-0:4.3.9-3.15 *
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 RedHat *
Red Hat Enterprise Linux ES version 2.1 RedHat *
Red Hat Enterprise Linux WS version 2.1 RedHat *
Red Hat Linux Advanced Workstation 2.1 RedHat *
Stronghold 4.0 for Red Hat Enterprise Linux AS (version 2.1) RedHat *
Php4 Ubuntu dapper *
Php4 Ubuntu edgy *
Php5 Ubuntu dapper *
Php5 Ubuntu devel *
Php5 Ubuntu edgy *
Php5 Ubuntu feisty *
Php5 Ubuntu gutsy *
Php5 Ubuntu hardy *
Php5 Ubuntu intrepid *
Php5 Ubuntu jaunty *
Php5 Ubuntu karmic *

References