CVE-2008-5557: Buffer Overflow
Heap-based buffer overflow in ext/mbstring/libmbfl/filters/mbfilterhtmlent.c in the mbstring extension in PHP 4.3.0 through 5.2.6 allows context-dependent attackers to execute arbitrary code via a crafted string containing an HTML entity, which is not properly handled during Unicode conversion, related to the (1) mbconvertencoding, (2) mbcheckencoding, (3) mbconvertvariables, and (4) mbparsestr functions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5557?
The severity of CVE-2008-5557 is critical due to its potential for arbitrary code execution.
How do I fix CVE-2008-5557?
To fix CVE-2008-5557, upgrade to a version of PHP higher than 5.2.7 or apply patches provided in later releases.
What are the affected versions in CVE-2008-5557?
CVE-2008-5557 affects PHP versions 4.3.0 to 5.2.6.
What types of attacks are possible with CVE-2008-5557?
CVE-2008-5557 allows context-dependent attackers to execute arbitrary code through crafted strings containing HTML entities.
Who is impacted by CVE-2008-5557?
Any users and applications utilizing vulnerable versions of PHP between 4.3.0 and 5.2.6 are at risk from CVE-2008-5557.