CVE Vulnerabilities

CVE-2007-4658

Published: Sep 04, 2007 | Modified: Oct 03, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The money_format function in PHP 5 before 5.2.4, and PHP 4 before 4.4.8, permits multiple (1) %i and (2) %n tokens, which has unknown impact and attack vectors, possibly related to a format string vulnerability.

Affected Software

Name Vendor Start Version End Version
Php Php 5.0.0 (including) 5.0.0 (including)
Php Php 5.0.0-beta1 (including) 5.0.0-beta1 (including)
Php Php 5.0.0-beta2 (including) 5.0.0-beta2 (including)
Php Php 5.0.0-beta3 (including) 5.0.0-beta3 (including)
Php Php 5.0.0-beta4 (including) 5.0.0-beta4 (including)
Php Php 5.0.0-rc1 (including) 5.0.0-rc1 (including)
Php Php 5.0.0-rc2 (including) 5.0.0-rc2 (including)
Php Php 5.0.0-rc3 (including) 5.0.0-rc3 (including)
Php Php 5.0.1 (including) 5.0.1 (including)
Php Php 5.0.2 (including) 5.0.2 (including)
Php Php 5.0.3 (including) 5.0.3 (including)
Php Php 5.0.4 (including) 5.0.4 (including)
Php Php 5.0.5 (including) 5.0.5 (including)
Php Php 5.1.0 (including) 5.1.0 (including)
Php Php 5.1.1 (including) 5.1.1 (including)
Php Php 5.1.2 (including) 5.1.2 (including)
Php Php 5.1.3 (including) 5.1.3 (including)
Php Php 5.1.4 (including) 5.1.4 (including)
Php Php 5.1.5 (including) 5.1.5 (including)
Php Php 5.1.6 (including) 5.1.6 (including)
Php Php 5.2.0 (including) 5.2.0 (including)
Php Php 5.2.1 (including) 5.2.1 (including)
Php Php 5.2.2 (including) 5.2.2 (including)
Php Php 5.2.3 (including) 5.2.3 (including)
Php Php 5.2.10 (including) 5.2.10 (including)
Php Php 5.2.11 (including) 5.2.11 (including)
Php Php 5.2.12 (including) 5.2.12 (including)
Php Php 5.2.13 (including) 5.2.13 (including)
Php Php 5.2.14 (including) 5.2.14 (including)
Php5 Ubuntu dapper *
Php5 Ubuntu edgy *
Php5 Ubuntu feisty *
Php5 Ubuntu gutsy *
Php5 Ubuntu upstream *
Red Hat Enterprise Linux 3 RedHat php-0:4.3.2-43.ent *
Red Hat Enterprise Linux 4 RedHat php-0:4.3.9-3.22.9 *
Red Hat Enterprise Linux 5 RedHat php-0:5.1.6-15.el5 *
Red Hat Web Application Stack for RHEL 4 RedHat php-0:5.1.6-3.el4s1.8 *

References