First published: Mon Mar 12 2007(Updated: )
The cpdf_open function in the ClibPDF (cpdf) extension in PHP 4.4.6 allows context-dependent attackers to obtain sensitive information (script source code) via a long string in the second argument.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP | =4.4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1412 is classified as a medium severity vulnerability.
To fix CVE-2007-1412, upgrade your PHP version to 5.0.0 or later.
CVE-2007-1412 affects PHP version 4.4.6.
CVE-2007-1412 can leak sensitive information, including script source code.
CVE-2007-1412 can be exploited by context-dependent attackers with control over input.