CVE Vulnerabilities

CVE-2007-5898

Published: Nov 20, 2007 | Modified: Oct 15, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

The (1) htmlentities and (2) htmlspecialchars functions in PHP before 5.2.5 accept partial multibyte sequences, which has unknown impact and attack vectors, a different issue than CVE-2006-5465.

Affected Software

Name Vendor Start Version End Version
Php Php * 5.2.4 (including)
Red Hat Enterprise Linux 2.1 RedHat php-0:4.1.2-2.20 *
Red Hat Enterprise Linux 3 RedHat php-0:4.3.2-48.ent *
Red Hat Enterprise Linux 4 RedHat php-0:4.3.9-3.22.12 *
Red Hat Enterprise Linux 5 RedHat php-0:5.1.6-20.el5_2.1 *
Red Hat Web Application Stack for RHEL 4 RedHat php-0:5.1.6-3.el4s1.10 *
Php5 Ubuntu dapper *
Php5 Ubuntu edgy *
Php5 Ubuntu feisty *
Php5 Ubuntu gutsy *
Php5 Ubuntu hardy *
Php5 Ubuntu upstream *

References