First published: Thu Aug 23 2007(Updated: )
Multiple buffer overflows in the php_ntuser component for PHP 5.2.3 allow context-dependent attackers to cause a denial of service or execute arbitrary code via long arguments to the (1) ntuser_getuserlist, (2) ntuser_getuserinfo, (3) ntuser_getusergroups, or (4) ntuser_getdomaincontroller functions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP | =5.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4507 has a high severity level due to its potential to cause denial of service and arbitrary code execution.
To fix CVE-2007-4507, upgrade to a later version of PHP beyond 5.2.3 where the vulnerabilities are patched.
CVE-2007-4507 affects the php_ntuser component specifically in PHP version 5.2.3.
Yes, CVE-2007-4507 can be exploited remotely by attackers sending long arguments to specific functions.
The functions involved in CVE-2007-4507 are ntuser_getuserlist, ntuser_getuserinfo, ntuser_getusergroups, and ntuser_getdomaincontroller.