CVE-2006-4482: Buffer Overflow
Published Aug 31, 2006
·Updated
Multiple heap-based buffer overflows in the (1) strrepeat and (2) wordwrap functions in ext/standard/string.c in PHP before 5.1.5, when used on a 64-bit system, have unspecified impact and attack vectors, a different vulnerability than CVE-2006-1990.
Affected Software
5 affected components
PHP PHP<5.1.5
Canonical Ubuntu Linux=5.04
Canonical Ubuntu Linux=5.10
Canonical Ubuntu Linux=6.06
Debian Debian Linux=3.1
Remediation
Patch Available
Patch Available
Event History
Aug 31, 2006
CVE Published
09:04 PM
Sep 1, 2006
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4482?
CVE-2006-4482 is classified as having unspecified impact and attack vectors due to multiple heap-based buffer overflows in PHP.
2
How do I fix CVE-2006-4482?
To fix CVE-2006-4482, upgrade PHP to version 5.1.5 or later.
3
Which versions of PHP are affected by CVE-2006-4482?
PHP versions prior to 5.1.5 are affected by CVE-2006-4482.
4
On which operating systems is CVE-2006-4482 a concern?
CVE-2006-4482 affects PHP installations on 64-bit systems, especially on Ubuntu and Debian Linux distributions.
5
What functions in PHP are vulnerable due to CVE-2006-4482?
The str_repeat and wordwrap functions in PHP are vulnerable due to CVE-2006-4482.