CVE-2007-4657 describes multiple integer overflow vulnerabilities in PHP versions prior to 4.4.8 and 5.2.4, affecting various distributions including Canonical and Debian. Remote attackers can exploit these flaws by providing a large 'len' value to the 'strspn' or 'strcspn' functions, leading to an out-of-bounds read. This can result in information disclosure (memory contents) or a denial of service (thread crash). The vulnerability has a CVSS score of 7.5, indicating high severity with a network-based attack vector and low attack complexity, requiring no authentication. The potential impact includes partial confidentiality, integrity, and availability compromise. Despite its severity, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Furthermore, the vulnerability has received minimal community discussion and media coverage, suggesting a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 4.4.8CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
>= 5.0.0, < 5.2.4CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
3.1CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:* | ||
6.06CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.