CVE-2007-4661
Summary
| CVE | CVE-2007-4661 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-09-04 22:17:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The chunk_split function in string.c in PHP 5.2.3 does not properly calculate the needed buffer size due to precision loss when performing integer arithmetic with floating point numbers, which has unknown attack vectors and impact, possibly resulting in a heap-based buffer overflow. NOTE: this is due to an incomplete fix for CVE-2007-2872. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: CWE-119 | CWE-399 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Ubuntu update for php - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| cvs.php.net/viewvc.cgi/php-src/ext/standard/string.c | af854a3a-2127-422b-91ae-364da2661108 | cvs.php.net | Exploit |
| [security-announce] SUSE Security Announcement: php4, php5 (SUSE-SA:2008 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| USN-549-2: PHP regression | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| SUSE update for php4 and php5 - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Gentoo Linux Documentation -- PHP: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | |
| USN-549-1: PHP vulnerabilities | Ubuntu security notices | af854a3a-2127-422b-91ae-364da2661108 | usn.ubuntu.com | |
| PHP Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch |
| rPath Update for Multiple php Packages - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Gentoo update for php - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Bug #173043 “php5 5.2.3-1ubuntu6.1 introduced segfault regressio...” : Bugs : “php5” package : Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | launchpad.net | |
| PHP: PHP 5.2.4 Release Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.php.net | Patch |
| issues.rpath.com/browse/RPL-1702 | af854a3a-2127-422b-91ae-364da2661108 | issues.rpath.com | |
| PHP: PHP 5 ChangeLog | af854a3a-2127-422b-91ae-364da2661108 | www.php.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Mandriva | 2007-09-18 | Vincent Danen | Not vulnerable. Mandriva has not issued an update to date to fix CVE-2007-2872 and the updates in progress are using a correct fix. |
| Red Hat | 2007-09-05 | Mark J Cox | Not vulnerable. Red Hat did not include an incomplete fix for CVE-2007-2872 for PHP in Red Hat Enterprise Linux or Red Hat Application Stack. |
There are currently no legacy QID mappings associated with this CVE.