7.5

CVE-2007-1285

Exploit

The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.

Data is provided by the National Vulnerability Database (NVD)
PhpPhp Version >= 4.0.0 < 4.4.7
PhpPhp Version >= 5.0.0 < 5.2.2
CanonicalUbuntu Linux Version7.10
NovellSuse Linux Version10.0
NovellSuse Linux Version10.1
SuseLinux Enterprise Server Version10 Updatesp1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 6.89% 0.91
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-674 Uncontrolled Recursion

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

http://secunia.com/advisories/24924
Vendor Advisory
Broken Link
http://secunia.com/advisories/24945
Vendor Advisory
Broken Link
http://www.securityfocus.com/archive/1/466166/100/0/threaded
Third Party Advisory
Broken Link
VDB Entry
http://secunia.com/advisories/26048
Vendor Advisory
Broken Link
http://secunia.com/advisories/24909
Vendor Advisory
Broken Link
http://secunia.com/advisories/24910
Vendor Advisory
Broken Link
http://secunia.com/advisories/24941
Vendor Advisory
Broken Link
http://secunia.com/advisories/25445
Vendor Advisory
Broken Link
http://secunia.com/advisories/26642
Vendor Advisory
Broken Link
http://secunia.com/advisories/27864
Vendor Advisory
Broken Link
http://secunia.com/advisories/28936
Vendor Advisory
Broken Link
http://www.php-security.org/MOPB/MOPB-03-2007.html
Vendor Advisory
Exploit
Broken Link
http://www.securityfocus.com/bid/22764
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id?1017771
Third Party Advisory
Broken Link
VDB Entry
https://launchpad.net/bugs/173043
Exploit
Issue Tracking