CVE-2007-1885
Summary
| CVE | CVE-2007-1885 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-04-06 01:19:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Integer overflow in the str_replace function in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 allows context-dependent attackers to execute arbitrary code via a single character search string in conjunction with a long replacement string, which overflows a 32 bit length counter. NOTE: this is probably the same issue as CVE-2007-0906.6. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Php | Php | 4.0.0 | All | All | All |
| Application | Php | Php | 4.0.1 | All | All | All |
| Application | Php | Php | 4.0.1 | patch1 | All | All |
| Application | Php | Php | 4.0.1 | patch2 | All | All |
| Application | Php | Php | 4.0.2 | All | All | All |
| Application | Php | Php | 4.0.3 | All | All | All |
| Application | Php | Php | 4.0.3 | patch1 | All | All |
| Application | Php | Php | 4.0.4 | All | All | All |
| Application | Php | Php | 4.0.4 | patch1 | All | All |
| Application | Php | Php | 4.0.5 | All | All | All |
| Application | Php | Php | 4.0.6 | All | All | All |
| Application | Php | Php | 4.0.7 | All | All | All |
| Application | Php | Php | 4.0.7 | rc1 | All | All |
| Application | Php | Php | 4.0.7 | rc2 | All | All |
| Application | Php | Php | 4.0.7 | rc3 | All | All |
| Application | Php | Php | 4.1.0 | All | All | All |
| Application | Php | Php | 4.1.1 | All | All | All |
| Application | Php | Php | 4.1.2 | All | All | All |
| Application | Php | Php | 4.2 | All | dev | All |
| Application | Php | Php | 4.2.0 | All | All | All |
| Application | Php | Php | 4.2.1 | All | All | All |
| Application | Php | Php | 4.2.2 | All | All | All |
| Application | Php | Php | 4.2.3 | All | All | All |
| Application | Php | Php | 4.3.0 | All | All | All |
| Application | Php | Php | 4.3.1 | All | All | All |
| Application | Php | Php | 4.3.10 | All | All | All |
| Application | Php | Php | 4.3.11 | All | All | All |
| Application | Php | Php | 4.3.2 | All | All | All |
| Application | Php | Php | 4.3.3 | All | All | All |
| Application | Php | Php | 4.3.4 | All | All | All |
| Application | Php | Php | 4.3.5 | All | All | All |
| Application | Php | Php | 4.3.6 | All | All | All |
| Application | Php | Php | 4.3.7 | All | All | All |
| Application | Php | Php | 4.3.8 | All | All | All |
| Application | Php | Php | 4.3.9 | All | All | All |
| Application | Php | Php | 4.4.0 | All | All | All |
| Application | Php | Php | 4.4.1 | All | All | All |
| Application | Php | Php | 4.4.2 | All | All | All |
| Application | Php | Php | 4.4.3 | All | All | All |
| Application | Php | Php | 4.4.4 | All | All | All |
| Application | Php | Php | 4.4.5 | All | All | All |
| Application | Php | Php | 4.4.6 | All | All | All |
| Application | Php | Php | 5.0 | rc1 | All | All |
| Application | Php | Php | 5.0 | rc2 | All | All |
| Application | Php | Php | 5.0 | rc3 | All | All |
| Application | Php | Php | 5.0.0 | All | All | All |
| Application | Php | Php | 5.0.0 | beta1 | All | All |
| Application | Php | Php | 5.0.0 | beta2 | All | All |
| Application | Php | Php | 5.0.0 | beta3 | All | All |
| Application | Php | Php | 5.0.0 | beta4 | All | All |
| Application | Php | Php | 5.0.0 | rc1 | All | All |
| Application | Php | Php | 5.0.0 | rc2 | All | All |
| Application | Php | Php | 5.0.0 | rc3 | All | All |
| Application | Php | Php | 5.0.1 | All | All | All |
| Application | Php | Php | 5.0.2 | All | All | All |
| Application | Php | Php | 5.0.3 | All | All | All |
| Application | Php | Php | 5.0.4 | All | All | All |
| Application | Php | Php | 5.0.5 | All | All | All |
| Application | Php | Php | 5.1.0 | All | All | All |
| Application | Php | Php | 5.1.1 | All | All | All |
| Application | Php | Php | 5.1.2 | All | All | All |
| Application | Php | Php | 5.1.3 | All | All | All |
| Application | Php | Php | 5.1.4 | All | All | All |
| Application | Php | Php | 5.1.5 | All | All | All |
| Application | Php | Php | 5.1.6 | All | All | All |
| Application | Php | Php | 5.2.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| HP Secure Web Server/Internet Express for Tru64 UNIX PHP Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| HPSBMA02215 SSRT071423 rev.1 - HP System Management Homepage (SMH) for Linux and Windows Running PHP, Remote Execution of Arbitrary Code - c01056506 - HP Business Support Center | af854a3a-2127-422b-91ae-364da2661108 | h20000.www2.hp.com | |
| HP System Management Homepage PHP Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| PHP: PHP 5.2.1 Release Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.php.net | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| HPSBTU02232 SSRT071429 rev.1 - Secure Web Server for HP Tru64 UNIX Powered by Apache (SWS) or HP Internet Express for Tru64 UNIX running PHP, Remote Arbitrary Code Execution, Unauthorized Disclosure of Information, or Denial of Service (DoS) - c01086137 - HP Business Support Center | af854a3a-2127-422b-91ae-364da2661108 | h20000.www2.hp.com | |
| PHP Str_Replace() Integer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| MOPB-39-2007:PHP str_replace() Memory Allocation Integer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.php-security.org | Exploit, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2007-05-01 | Mark J Cox | This CVE name is a duplicate as the vulnerability is addressed by CVE-2007-0906. |
There are currently no legacy QID mappings associated with this CVE.