CVE Vulnerabilities

CVE-2009-0754

Use of Externally-Controlled Format String

Published: Mar 03, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
2.1 MODERATE
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.

Weakness

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Affected Software

NameVendorStart VersionEnd Version
PhpPhp4.4.4 (including)4.4.4 (including)
PhpPhp5.1.6 (including)5.1.6 (including)
Red Hat Enterprise Linux 3RedHatphp-0:4.3.2-51.ent*
Red Hat Enterprise Linux 4RedHatphp-0:4.3.9-3.22.15*
Red Hat Enterprise Linux 5RedHatphp-0:5.1.6-23.2.el5_3*
Php5Ubuntudapper*
Php5Ubuntudevel*
Php5Ubuntugutsy*
Php5Ubuntuhardy*
Php5Ubuntuintrepid*

Potential Mitigations

References