First published: Mon Apr 02 2007(Updated: )
Buffer overflow in the php_stream_filter_create function in PHP 5 before 5.2.1 allows remote attackers to cause a denial of service (application crash) via a php://filter/ URL that has a name ending in the '.' character.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP | =5.1.5 | |
PHP | =5.1.2 | |
PHP | =5.1.1 | |
PHP | =5.1.6 | |
PHP | =5.0.5 | |
PHP | =5.0.1 | |
PHP | =5.1.4 | |
PHP | =5.0.4 | |
PHP | =5.0.3 | |
PHP | =5.1.0 | |
PHP | =5.2.0 | |
PHP | =5.1.3 | |
PHP | =5.0.2 | |
PHP | =5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1824 is classified as a denial of service vulnerability that causes an application crash.
You can resolve CVE-2007-1824 by upgrading to PHP version 5.2.1 or later.
CVE-2007-1824 affects PHP versions 5.0.0 through 5.2.0.
CVE-2007-1824 enables remote attackers to trigger a denial of service through a specially crafted php://filter URL.
CVE-2007-1824 is a remote vulnerability, allowing attackers to exploit it over the network.