CVE Vulnerabilities

CVE-2007-4658

Published: Sep 04, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The money_format function in PHP 5 before 5.2.4, and PHP 4 before 4.4.8, permits multiple (1) %i and (2) %n tokens, which has unknown impact and attack vectors, possibly related to a format string vulnerability.

Affected Software

NameVendorStart VersionEnd Version
PhpPhp5.0.0 (including)5.0.0 (including)
PhpPhp5.0.0-beta1 (including)5.0.0-beta1 (including)
PhpPhp5.0.0-beta2 (including)5.0.0-beta2 (including)
PhpPhp5.0.0-beta3 (including)5.0.0-beta3 (including)
PhpPhp5.0.0-beta4 (including)5.0.0-beta4 (including)
PhpPhp5.0.0-rc1 (including)5.0.0-rc1 (including)
PhpPhp5.0.0-rc2 (including)5.0.0-rc2 (including)
PhpPhp5.0.0-rc3 (including)5.0.0-rc3 (including)
PhpPhp5.0.1 (including)5.0.1 (including)
PhpPhp5.0.2 (including)5.0.2 (including)
PhpPhp5.0.3 (including)5.0.3 (including)
PhpPhp5.0.4 (including)5.0.4 (including)
PhpPhp5.0.5 (including)5.0.5 (including)
PhpPhp5.1.0 (including)5.1.0 (including)
PhpPhp5.1.1 (including)5.1.1 (including)
PhpPhp5.1.2 (including)5.1.2 (including)
PhpPhp5.1.3 (including)5.1.3 (including)
PhpPhp5.1.4 (including)5.1.4 (including)
PhpPhp5.1.5 (including)5.1.5 (including)
PhpPhp5.1.6 (including)5.1.6 (including)
PhpPhp5.2.0 (including)5.2.0 (including)
PhpPhp5.2.1 (including)5.2.1 (including)
PhpPhp5.2.2 (including)5.2.2 (including)
PhpPhp5.2.3 (including)5.2.3 (including)
PhpPhp5.2.10 (including)5.2.10 (including)
PhpPhp5.2.11 (including)5.2.11 (including)
PhpPhp5.2.12 (including)5.2.12 (including)
PhpPhp5.2.13 (including)5.2.13 (including)
PhpPhp5.2.14 (including)5.2.14 (including)
Red Hat Enterprise Linux 3RedHatphp-0:4.3.2-43.ent*
Red Hat Enterprise Linux 4RedHatphp-0:4.3.9-3.22.9*
Red Hat Enterprise Linux 5RedHatphp-0:5.1.6-15.el5*
Red Hat Web Application Stack for RHEL 4RedHatphp-0:5.1.6-3.el4s1.8*
Php5Ubuntudapper*
Php5Ubuntuedgy*
Php5Ubuntufeisty*
Php5Ubuntugutsy*
Php5Ubuntuupstream*

References