CVE-2007-3806
Summary
| CVE | CVE-2007-3806 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-07-17 00:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The glob function in PHP 5.2.3 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via an invalid value of the flags parameter, probably related to memory corruption or an invalid read on win32 platforms, and possibly related to lack of initialization for a glob structure. |
Risk And Classification
Primary CVSS: v2.0 6.8 from [email protected]
AV:N/AC:M/Au:N/C:P/I:P/A:P
Problem Types: CWE-20 | CWE-399 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-1578-1 php4 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Debian update for php4 - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| PHP 5.2.3 glob() Denial of Service Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| PHP "glob()" Code Execution Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| PHP 5.2.3 and Prior Versions Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| cvs.php.net/viewvc.cgi/php-src/ext/standard/dir.c | af854a3a-2127-422b-91ae-364da2661108 | cvs.php.net | |
| Gentoo Linux Documentation -- PHP: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | |
| PHP Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| PHP Glob() Function Arbitrary Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| osvdb.org/36085 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Gentoo update for php - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Debian -- Security Information -- DSA-1572-1 php5 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| PHP: PHP 5.2.4 Release Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.php.net | |
| Debian update for php5 - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| cvs.php.net/viewvc.cgi/php-src/ext/standard/dir.c | af854a3a-2127-422b-91ae-364da2661108 | cvs.php.net | |
| PHP: PHP 5 ChangeLog | af854a3a-2127-422b-91ae-364da2661108 | www.php.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2007-09-05 | Mark J Cox | Not vulnerable. This issue only affected PHP on Windows platforms. |
There are currently no legacy QID mappings associated with this CVE.