First published: Sat Mar 10 2007(Updated: )
Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1, allows remote attackers to execute arbitrary code via a long zip:// URL, as demonstrated by actively triggering URL access from a remote PHP interpreter via avatar upload or blog pingback.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PECL ZIP 1.8.3 | ||
PHP | =5.2.0 | |
PHP | =5.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1399 has a high severity rating due to the potential for remote code execution.
To fix CVE-2007-1399, upgrade PECL ZIP to version 1.8.4 or later and ensure your PHP version is above 5.2.1.
CVE-2007-1399 affects PECL ZIP version 1.8.3 and PHP versions 5.2.0 and 5.2.1.
Yes, if exploited, CVE-2007-1399 can allow attackers to execute arbitrary code, potentially leading to data breaches.
While CVE-2007-1399 is an older vulnerability, systems running the affected software versions remain at risk if not updated.