[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249966

 
 

909

 
 

195636

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2007-1380Date: (C)2007-03-09   (M)2023-12-22


The php_binary serialization handler in the session extension in PHP before 4.4.5, and 5.x before 5.2.1, allows context-dependent attackers to obtain sensitive information (memory contents) via a serialized variable entry with a large length value, which triggers a buffer over-read.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
BID-22805
SECUNIA-24514
SECUNIA-24606
SECUNIA-25025
SECUNIA-25056
SECUNIA-25057
SECUNIA-25062
SECUNIA-25423
SECUNIA-25850
EXPLOIT-DB-3413
ADV-2007-1991
ADV-2007-2374
DSA-1282
DSA-1283
GLSA-200703-21
HPSBTU02232
SSRT071423
SUSE-SA:2007:020
SUSE-SA:2007:032
USN-455-1
http://www.php-security.org/MOPB/MOPB-10-2007.html
oval:org.mitre.oval:def:10792

CPE    59
cpe:/a:php:php:5.0.0:rc3
cpe:/a:php:php:5.0.0:rc2
cpe:/a:php:php:5.0.0:rc1
cpe:/a:php:php:5.1.4
...

© SecPod Technologies