CVE-2007-4887: Input Validation
Published Sep 14, 2007
·Updated
The dl function in PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in the library parameter. NOTE: there are limited usage scenarios under which this would be a vulnerability.
Affected Software
1 affected component
PHP PHP<=5.2.4
Event History
Sep 14, 2007
CVE Published
12:17 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4887?
CVE-2007-4887 has been classified with a severity that can lead to denial of service, causing application crashes.
2
How do I fix CVE-2007-4887?
To mitigate CVE-2007-4887, upgrade PHP to version 5.2.5 or later.
3
What versions of PHP are affected by CVE-2007-4887?
CVE-2007-4887 affects PHP versions up to and including 5.2.4.
4
What type of attack is associated with CVE-2007-4887?
CVE-2007-4887 allows context-dependent attackers to exploit a long string in the library parameter to cause denial of service.
5
Is CVE-2007-4887 a widely exploitable vulnerability?
CVE-2007-4887 is considered to have limited usage scenarios under which it can be exploited.