First published: Sat Mar 10 2007(Updated: )
Buffer overflow in the crack extension (CrackLib), as bundled with PHP 4.4.6 and other versions before 5.0.0, might allow local users to gain privileges via a long argument to the crack_opendict function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP | =4.4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1401 is classified as having a medium severity due to its potential to allow local privilege escalation.
To fix CVE-2007-1401, upgrade PHP to version 5.0.0 or later, where the vulnerability is resolved.
CVE-2007-1401 affects PHP version 4.4.6 and earlier versions before 5.0.0.
CVE-2007-1401 is primarily a local exploit, meaning it requires local access to the system to take advantage of the buffer overflow.
If exploited, CVE-2007-1401 could allow an attacker to gain elevated privileges on the affected system.