CVE-2007-1825: Buffer Overflow
Published Apr 2, 2007
·Updated
Buffer overflow in the imapmailcompose function in PHP 5 before 5.2.1, and PHP 4 before 4.4.5, allows remote attackers to execute arbitrary code via a long boundary string in a type.parameters field. NOTE: as of 20070411, it appears that this issue might be subsumed by CVE-2007-0906.3.
Affected Software
56 affected components
PHP PHP=4.3.9
PHP PHP=5.1.5
PHP PHP=5.1.2
PHP PHP=4.2.0
PHP PHP=5.1.1
PHP PHP=4.4.4
PHP PHP=4.1.0
PHP PHP=5.1.6
PHP PHP=4.3.4
PHP PHP=4.0.4
PHP PHP=4.3.0
PHP PHP=4.0.5
PHP PHP=5.0-rc1
PHP PHP=5.0.5
PHP PHP=4.3.6
PHP PHP=5.0.1
PHP PHP=5.1.4
PHP PHP=4.0.7-rc2
PHP PHP=4.3.7
PHP PHP=5.0.4
PHP PHP=4.0.7-rc1
PHP PHP=4.2.2
PHP PHP=4.4.2
PHP PHP=4.3.2
PHP PHP=4.3.11
PHP PHP=4.0.0
PHP PHP=4.0.3-patch1
PHP PHP=4.0.7
PHP PHP=4.0.2
PHP PHP=4.3.3
PHP PHP=5.0-rc3
PHP PHP=4.1.1
PHP PHP=4.4.3
PHP PHP=5.0.3
PHP PHP=4.2.3
PHP PHP=5.1.0
PHP PHP=4.0.1-patch1
PHP PHP=4.0.1-patch2
PHP PHP=4.0.6
PHP PHP=5.0-rc2
PHP PHP=4.1.2
PHP PHP=4.0.7-rc3
PHP PHP=4.3.1
PHP PHP=5.1.3
PHP PHP=4.4.0
PHP PHP=4.3.10
PHP PHP=4.2.1
PHP PHP=4.0.4-patch1
PHP PHP=4.0.1
PHP PHP=5.0.2
PHP PHP=4.2
PHP PHP=4.4.1
PHP PHP=4.0.3
PHP PHP=5.0.0
PHP PHP=4.3.8
PHP PHP=4.3.5
Event History
Apr 2, 2007
CVE Published
11:19 PM
Apr 3, 2007
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1825?
CVE-2007-1825 has a critical severity rating due to its potential for remote code execution.
2
How do I fix CVE-2007-1825?
To fix CVE-2007-1825, upgrade to PHP 5.2.1 or later, or PHP 4.4.5 or later.
3
What versions of PHP are affected by CVE-2007-1825?
CVE-2007-1825 affects PHP versions 4.0.0 to 4.4.4 and 5.0.0 to 5.1.6.
4
Can CVE-2007-1825 lead to data breaches?
Yes, CVE-2007-1825 can potentially lead to data breaches through arbitrary code execution.
5
Is CVE-2007-1825 being actively exploited?
While there have been reports of exploitation, it is essential to patch vulnerable versions to mitigate the risk.