Out-of-Bounds Affecting php package, versions <0:5.1.6-3.el4s1.5


Severity

Recommended
0.0
high
0
10

Based on Red Hat Enterprise Linux security rating.

Threat Intelligence

EPSS
1.08% (77th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL10-PHP-9865492
  • published28 Apr 2025
  • disclosed14 Feb 2007

Introduced: 14 Feb 2007

CVE-2007-0906  (opens in a new tab)
CWE-119  (opens in a new tab)

How to fix?

Upgrade RHEL:10 php to version 0:5.1.6-3.el4s1.5 or higher.
This issue was patched in RHSA-2007:0088.

NVD Description

Note: Versions mentioned in the description apply only to the upstream php package and not the php package as distributed by RHEL. See How to fix? for RHEL:10 relevant fixed versions and status.

Multiple buffer overflows in PHP before 5.2.1 allow attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors in the (1) session, (2) zip, (3) imap, and (4) sqlite extensions; (5) stream filters; and the (6) str_replace, (7) mail, (8) ibase_delete_user, (9) ibase_add_user, and (10) ibase_modify_user functions. NOTE: vector 6 might actually be an integer overflow (CVE-2007-1885). NOTE: as of 20070411, vector (3) might involve the imap_mail_compose function (CVE-2007-1825).

References

CVSS Base Scores

version 3.1