CVE-2007-1883: High severity PHP PHP vulnerability
PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to read arbitrary memory locations via an interruption that triggers a user space error handler that changes a parameter to an arbitrary pointer, as demonstrated via the iptcembed function, which calls certain convertto functions with its input parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1883?
CVE-2007-1883 has a moderate severity level as it allows context-dependent attackers to read arbitrary memory locations.
How do I fix CVE-2007-1883?
To fix CVE-2007-1883, upgrade PHP to a version that is not affected, such as PHP 5.2.2 or later.
What versions of PHP are affected by CVE-2007-1883?
CVE-2007-1883 affects PHP versions 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1.
What type of vulnerability is CVE-2007-1883?
CVE-2007-1883 is a memory-related vulnerability that allows reading arbitrary memory locations through a user space error handler.
Can CVE-2007-1883 lead to other attacks?
Yes, CVE-2007-1883 can potentially lead to further exploitation by exposing sensitive data from memory.