CVE-2002-2215: Medium severity PHP PHP vulnerability
Published Dec 31, 2002
·Updated
The imapheader function in the IMAP functionality for PHP before 4.3.0 allows remote attackers to cause a denial of service via an e-mail message with a large number of "To" addresses, which triggers an error in the rfc822writeaddress function.
Affected Software
49 affected components
PHP PHP=3.0
PHP PHP=4.0-beta1
PHP PHP=3.0.5
PHP PHP=3.0.11
PHP PHP=4.0-beta4
PHP PHP=4.2.0
PHP PHP=3.0.1
PHP PHP=3.0.2
PHP PHP=4.1.0
PHP PHP=4.0.4
PHP PHP=4.0.5
PHP PHP=3.0.8
PHP PHP<=4.2.3
PHP PHP=3.0.13
PHP PHP=4.0.7-rc2
PHP PHP=4.0.7-rc1
PHP PHP=4.2.2
PHP PHP=4.0-rc1
PHP PHP=3.0.7
PHP PHP=3.0.6
PHP PHP=4.0.3-patch1
PHP PHP=3.0.17
PHP PHP=4.0.7
PHP PHP=4.0.2
PHP PHP=4.1.1
PHP PHP=3.0.15
PHP PHP=3.0.16
PHP PHP=3.0.10
PHP PHP=3.0.4
PHP PHP=4.0.1-patch1
PHP PHP=4.0
PHP PHP=4.0-beta2
PHP PHP=4.0.1-patch2
PHP PHP=4.0.6
PHP PHP=4.1.2
PHP PHP=4.0.7-rc3
PHP PHP=4.0-rc2
PHP PHP=3.0.18
PHP PHP=4.0-beta_4_patch1
PHP PHP=4.2.1
PHP PHP=4.0.4-patch1
PHP PHP=4.0.1
PHP PHP=3.0.12
PHP PHP=4.2
PHP PHP=4.0-beta3
PHP PHP=4.0.3
PHP PHP=3.0.14
PHP PHP=3.0.9
PHP PHP=3.0.3
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Jun 15, 2006
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-2215?
CVE-2002-2215 is classified as a denial of service vulnerability.
2
How do I fix CVE-2002-2215?
To fix CVE-2002-2215, upgrade to PHP version 4.3.0 or later.
3
What are the affected PHP versions for CVE-2002-2215?
CVE-2002-2215 affects PHP versions prior to 4.3.0, including 3.0.x and 4.0.x.
4
Can CVE-2002-2215 be exploited remotely?
Yes, CVE-2002-2215 can be exploited remotely through crafted email messages.
5
What is the impact of exploiting CVE-2002-2215?
Exploiting CVE-2002-2215 can lead to a denial of service, causing the application to become unresponsive.