CVE-2007-1376 Affecting php package, versions [,4.4.5)[5.2.0,5.2.1)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
5.68% (94th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-PHP-2335158
  • published12 Jan 2022
  • disclosed10 Mar 2007
  • creditUnknown

Introduced: 10 Mar 2007

CVE-2007-1376  (opens in a new tab)

How to fix?

Upgrade php to version 4.4.5, 5.2.1 or higher.

Overview

The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspond to a shmop resource, which allows context-dependent attackers to read and write arbitrary memory locations via arguments associated with an inappropriate resource, as demonstrated by a GD Image resource.

CVSS Scores

version 3.1