CVE-2002-1396: Buffer Overflow
Published Jan 17, 2003
·Updated
Heap-based buffer overflow in the wordwrap function in PHP after 4.1.2 and before 4.3.0 may allow attackers to cause a denial of service or execute arbitrary code.
Affected Software
5 affected components
PHP PHP=4.2.0
PHP PHP=4.2.2
PHP PHP=4.2.3
PHP PHP=4.1.2
PHP PHP=4.2.1
Remediation
Patch Available
Patch Available
Event History
Jan 17, 2003
CVE Published
05:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1396?
CVE-2002-1396 has a high severity rating due to its potential to allow denial of service or arbitrary code execution.
2
How do I fix CVE-2002-1396?
To fix CVE-2002-1396, upgrade PHP to a version later than 4.3.0.
3
Which versions of PHP are affected by CVE-2002-1396?
CVE-2002-1396 affects PHP versions 4.1.2 to 4.2.3.
4
Can CVE-2002-1396 lead to remote code execution?
Yes, CVE-2002-1396 can potentially allow an attacker to execute arbitrary code remotely.
5
What mitigation strategies exist for CVE-2002-1396?
Mitigation strategies include updating PHP to a secure version and applying any available security patches.