CVE-2008-3659
Summary
| CVE | CVE-2008-3659 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-08-15 00:41:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Buffer overflow in the memnstr function in PHP 4.4.x before 4.4.9 and PHP 5.6 through 5.2.6 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via the delimiter argument to the explode function. NOTE: the scope of this issue is limited since most applications would not use an attacker-controlled delimiter, but local attacks against safe_mode are feasible. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:N/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Php | Php | 4.4.0 | All | All | All |
| Application | Php | Php | 4.4.1 | All | All | All |
| Application | Php | Php | 4.4.2 | All | All | All |
| Application | Php | Php | 4.4.3 | All | All | All |
| Application | Php | Php | 4.4.4 | All | All | All |
| Application | Php | Php | 4.4.5 | All | All | All |
| Application | Php | Php | 4.4.6 | All | All | All |
| Application | Php | Php | 4.4.7 | All | All | All |
| Application | Php | Php | 4.4.8 | All | All | All |
| Application | Php | Php | 5.2.0 | All | All | All |
| Application | Php | Php | 5.2.1 | All | All | All |
| Application | Php | Php | 5.2.2 | All | All | All |
| Application | Php | Php | 5.2.3 | All | All | All |
| Application | Php | Php | 5.2.4 | All | All | All |
| Application | Php | Php | 5.2.5 | All | All | All |
| Application | Php | Php | 5.2.6 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Gentoo Bug 234102 - dev-lang/php < 5.2.6-r6: arbitrary code execution, DoS, safe_mode bypass (CVE-2008-{3658,3659,3660}) | af854a3a-2127-422b-91ae-364da2661108 | bugs.gentoo.org | |
| Advisories | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| oss-security - Re: CVE request: php-5.2.6 overflow issues | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| SUSE Update for Multiple Packages - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| APPLE-SA-2009-05-12 Security Update 2009-002 / Mac OS X v10.5.7 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| SecurityTracker.com Archives - PHP Buffer Overflow in explode() Function May Let Users Bypass Safe Mode Restrictions | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| About the security content of Security Update 2009-002 / Mac OS X v10.5.7 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| SUSE Update for Multiple Packages - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Advisories | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2008:018 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| '[security bulletin] HPSBUX02465 SSRT090192 rev.1 - HP-UX Running Apache-based Web Server, Remote Den' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Debian -- Security Information -- DSA-1647-1 php5 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Apple Mac OS X Security Update Fixes Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Support / Security / Advisories / / MDVSA-2009:024 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| marc.info | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| PHP: News Archive - 2008 | af854a3a-2127-422b-91ae-364da2661108 | www.php.net | Patch |
| Advisories | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| php.cvs: cvs: php-src(PHP_5_2) /ext/standard/tests/strings explode_bug.phpt ZendEngine2 zend_operators.h | af854a3a-2127-422b-91ae-364da2661108 | news.php.net | |
| oss-security - CVE request: php-5.2.6 overflow issues | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| oss-security - Re: CVE request: php-5.2.6 overflow issues | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Advisories:rPSA-2009-0035 - rPath Wiki | af854a3a-2127-422b-91ae-364da2661108 | wiki.rpath.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| oss-security - Re: CVE request: php-5.2.6 overflow issues | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| PHP: Multiple vulnerabilities — Gentoo Linux Documentation | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| HP-UX Apache Web Server Suite Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| osvdb.org/47483 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Gentoo update for php - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2008:021 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| US-CERT Technical Cyber Security Alert TA09-133A -- Apple Updates for Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2017-08-07 | Joshua Bressers | The PHP interpreter does not offer a reliable sandboxed security layer (as found in, say, a JVM) in which untrusted scripts can be run any script run by the PHP interpreter must be trusted with the privileges of the interpreter itself. We therefore do not classify this issue as security-sensitive since no trust boundary is crossed. |
There are currently no legacy QID mappings associated with this CVE.