9.3

CVE-2006-4482

Multiple heap-based buffer overflows in the (1) str_repeat and (2) wordwrap functions in ext/standard/string.c in PHP before 5.1.5, when used on a 64-bit system, have unspecified impact and attack vectors, a different vulnerability than CVE-2006-1990.

Data is provided by the National Vulnerability Database (NVD)
PhpPhp Version < 5.1.5
CanonicalUbuntu Linux Version5.04
CanonicalUbuntu Linux Version5.10
CanonicalUbuntu Linux Version6.06
DebianDebian Linux Version3.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.46% 0.871
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

http://secunia.com/advisories/21546
Patch
Vendor Advisory
Not Applicable
http://www.php.net/ChangeLog-5.php#5.1.5
Vendor Advisory
Release Notes
http://www.php.net/release_5_1_5.php
Patch
Vendor Advisory
Release Notes
http://secunia.com/advisories/22225
Vendor Advisory
Not Applicable
http://secunia.com/advisories/22004
Vendor Advisory
Not Applicable
http://secunia.com/advisories/22069
Vendor Advisory
Not Applicable
http://secunia.com/advisories/22440
Vendor Advisory
Not Applicable
http://secunia.com/advisories/21768
Vendor Advisory
Not Applicable
http://securitytracker.com/id?1016984
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/bid/19582
Third Party Advisory
VDB Entry