CVE-2007-1582: Medium severity PHP PHP vulnerability
The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting certain functions in the GD (ext/gd) extension and unspecified other extensions via a userspace error handler, which can be used to destroy and modify internal resources.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1582?
CVE-2007-1582 is a critical vulnerability that can allow context-dependent attackers to execute arbitrary code.
How do I fix CVE-2007-1582?
To mitigate CVE-2007-1582, upgrade to a patched version of PHP that is not vulnerable, specifically versions above 5.2.1.
What versions of PHP are affected by CVE-2007-1582?
CVE-2007-1582 affects PHP versions from 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1.
What types of attacks are possible with CVE-2007-1582?
CVE-2007-1582 allows attackers to exploit the GD extension and potentially execute arbitrary code due to userspace error handling.
Is CVE-2007-1582 applicable to PHP 5.3 and later versions?
No, CVE-2007-1582 does not apply to PHP versions 5.3 and later, which are not affected by this vulnerability.