CVE-2007-1887: Buffer Overflow
Published Apr 6, 2007
·Updated
Buffer overflow in the sqlitedecodebinary function in the bundled sqlite library in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 allows context-dependent attackers to execute arbitrary code via an empty value of the in parameter, as demonstrated by calling the sqliteudfdecodebinary function with a 0x01 character.
Affected Software
6 affected components
PHP PHP>=4.0<4.4.5
PHP PHP>=5.0.0<5.2.3
Canonical Ubuntu Linux=7.04
Canonical Ubuntu Linux=6.10
Canonical Ubuntu Linux=6.06
Debian Debian Linux=4.0
Event History
Apr 6, 2007
CVE Published
01:19 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
How can I determine if my system is vulnerable to CVE-2007-1887?
To determine if your system is vulnerable to CVE-2007-1887, check the version of PHP and the associated libraries installed on your system.