CVE-2003-0166: High severity PHP PHP vulnerability
Published Mar 27, 2003
·Updated
Integer signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via negative arguments to functions such as (1) socketrecv, (2) socketrecvfrom, and possibly other functions.
Affected Software
17 affected components
PHP PHP=4.2.0
PHP PHP=4.1.0
PHP PHP=4.0.4
PHP PHP=4.3.0
PHP PHP=4.0.5
PHP PHP=4.2.2
PHP PHP=4.0.7
PHP PHP=4.0.2
PHP PHP=4.1.1
PHP PHP=4.0.6
PHP PHP=4.2.3
PHP PHP=4.3.1
PHP PHP=4.0.3
PHP PHP=4.2.1
PHP PHP=4.0
PHP PHP=4.0.1
PHP PHP=4.1.2
Event History
Mar 27, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Apr 2, 2003
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0166?
CVE-2003-0166 has a medium severity rating due to its potential to cause denial of service and arbitrary code execution.
2
How do I fix CVE-2003-0166?
To fix CVE-2003-0166, upgrade your PHP version to at least 4.3.2 or later.
3
Which PHP versions are affected by CVE-2003-0166?
CVE-2003-0166 affects PHP versions 4.0.0 to 4.3.1 inclusive.
4
What types of attacks can exploit CVE-2003-0166?
CVE-2003-0166 can be exploited through malformed negative arguments to certain socket functions.
5
Is CVE-2003-0166 a remote vulnerability?
Yes, CVE-2003-0166 is a remote vulnerability that allows attackers to exploit the issue over the network.