Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 and PHP 4 before 4.4.8 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via the (1) chunks, (2) srclen, and (3) chunklen arguments.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Php | Php | * | 4.4.7 (including) |
Php | Php | 5.0.0 (including) | 5.0.0 (including) |
Php | Php | 5.0.1 (including) | 5.0.1 (including) |
Php | Php | 5.0.2 (including) | 5.0.2 (including) |
Php | Php | 5.0.3 (including) | 5.0.3 (including) |
Php | Php | 5.0.4 (including) | 5.0.4 (including) |
Php | Php | 5.0.5 (including) | 5.0.5 (including) |
Php | Php | 5.1.0 (including) | 5.1.0 (including) |
Php | Php | 5.1.1 (including) | 5.1.1 (including) |
Php | Php | 5.1.2 (including) | 5.1.2 (including) |
Php | Php | 5.1.3 (including) | 5.1.3 (including) |
Php | Php | 5.1.4 (including) | 5.1.4 (including) |
Php | Php | 5.1.5 (including) | 5.1.5 (including) |
Php | Php | 5.1.6 (including) | 5.1.6 (including) |
Php | Php | 5.2.0 (including) | 5.2.0 (including) |
Php | Php | 5.2.1 (including) | 5.2.1 (including) |
Php | Php | 5.2.2 (including) | 5.2.2 (including) |
Red Hat Enterprise Linux 2.1 | RedHat | php-0:4.1.2-2.19 | * |
Red Hat Enterprise Linux 3 | RedHat | php-0:4.3.2-43.ent | * |
Red Hat Enterprise Linux 4 | RedHat | php-0:4.3.9-3.22.9 | * |
Red Hat Enterprise Linux 5 | RedHat | php-0:5.1.6-15.el5 | * |
Red Hat Web Application Stack for RHEL 4 | RedHat | php-0:5.1.6-3.el4s1.8 | * |
Php5 | Ubuntu | dapper | * |
Php5 | Ubuntu | edgy | * |
Php5 | Ubuntu | feisty | * |
Php5 | Ubuntu | gutsy | * |
Php5 | Ubuntu | upstream | * |