5

CVE-2007-1717

Exploit
The mail function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 truncates e-mail messages at the first ASCIIZ ('\0') byte, which might allow context-dependent attackers to prevent intended information from being delivered in e-mail messages.  NOTE: this issue might be security-relevant in cases when the trailing contents of e-mail messages are important, such as logging information or if the message is expected to be well-formed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Php ≫ Php Version 4.0
Php ≫ Php Version 4.0 Update beta_4_patch1
Php ≫ Php Version 4.0 Update beta1
Php ≫ Php Version 4.0 Update beta2
Php ≫ Php Version 4.0 Update beta3
Php ≫ Php Version 4.0 Update beta4
Php ≫ Php Version 4.0 Update rc1
Php ≫ Php Version 4.0 Update rc2
Php ≫ Php Version 4.0.0
Php ≫ Php Version 4.0.1
Php ≫ Php Version 4.0.1 Update patch1
Php ≫ Php Version 4.0.1 Update patch2
Php ≫ Php Version 4.0.2
Php ≫ Php Version 4.0.3
Php ≫ Php Version 4.0.3 Update patch1
Php ≫ Php Version 4.0.4
Php ≫ Php Version 4.0.4 Update patch1
Php ≫ Php Version 4.0.5
Php ≫ Php Version 4.0.6
Php ≫ Php Version 4.0.7
Php ≫ Php Version 4.0.7 Update rc1
Php ≫ Php Version 4.0.7 Update rc2
Php ≫ Php Version 4.0.7 Update rc3
Php ≫ Php Version 4.1.0
Php ≫ Php Version 4.1.1
Php ≫ Php Version 4.1.2
Php ≫ Php Version 4.2 Edition dev
Php ≫ Php Version 4.2.0
Php ≫ Php Version 4.2.1
Php ≫ Php Version 4.2.2
Php ≫ Php Version 4.2.3
Php ≫ Php Version 4.3.0
Php ≫ Php Version 4.3.1
Php ≫ Php Version 4.3.2
Php ≫ Php Version 4.3.3
Php ≫ Php Version 4.3.4
Php ≫ Php Version 4.3.5
Php ≫ Php Version 4.3.6
Php ≫ Php Version 4.3.7
Php ≫ Php Version 4.3.8
Php ≫ Php Version 4.3.9
Php ≫ Php Version 4.3.10
Php ≫ Php Version 4.3.11
Php ≫ Php Version 4.4.0
Php ≫ Php Version 4.4.1
Php ≫ Php Version 4.4.2
Php ≫ Php Version 4.4.3
Php ≫ Php Version 4.4.4
Php ≫ Php Version 4.4.5
Php ≫ Php Version 4.4.6
Php ≫ Php Version 5.0 Update rc1
Php ≫ Php Version 5.0 Update rc2
Php ≫ Php Version 5.0 Update rc3
Php ≫ Php Version 5.0.0
Php ≫ Php Version 5.0.0 Update beta1
Php ≫ Php Version 5.0.0 Update beta2
Php ≫ Php Version 5.0.0 Update beta3
Php ≫ Php Version 5.0.0 Update beta4
Php ≫ Php Version 5.0.0 Update rc1
Php ≫ Php Version 5.0.0 Update rc2
Php ≫ Php Version 5.0.0 Update rc3
Php ≫ Php Version 5.0.1
Php ≫ Php Version 5.0.2
Php ≫ Php Version 5.0.3
Php ≫ Php Version 5.0.4
Php ≫ Php Version 5.0.5
Php ≫ Php Version 5.1.0
Php ≫ Php Version 5.1.1
Php ≫ Php Version 5.1.2
Php ≫ Php Version 5.1.3
Php ≫ Php Version 5.1.4
Php ≫ Php Version 5.1.5
Php ≫ Php Version 5.1.6
Php ≫ Php Version 5.2.0
Php ≫ Php Version 5.2.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.65% 0.906
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://docs.info.apple.com/article.html?artnum=306172
http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html
http://secunia.com/advisories/26235
http://www.securityfocus.com/bid/25159
http://www.vupen.com/english/advisories/2007/2732
http://secunia.com/advisories/25056
http://www.novell.com/linux/security/advisories/2007_32_php.html
http://secunia.com/advisories/25445
http://security.gentoo.org/glsa/glsa-200705-19.xml
http://us2.php.net/releases/4_4_7.php
http://us2.php.net/releases/5_2_2.php
http://www.php-security.org/MOPB/MOPB-33-2007.html
Exploit
http://www.securityfocus.com/bid/23146
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/33518