Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2002-1396

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2002-1396
Last Modified 05 Sep 2008 04:30:29
Published 17 Jan 2003 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2002-1396

Summary

Heap-based buffer overflow in the wordwrap function in PHP after 4.1.2 and before 4.3.0 may allow attackers to cause a denial of service or execute arbitrary code.

Vulnerable Systems

Application

  • Php 4.1.2

  • Php 4.2.0

  • Php 4.2.1

  • Php 4.2.2

  • Php 4.2.3


References

BID - 6488

CONFIRM - http://bugs.php.net/bug.php?id=20927

XF - php-wordwrap-bo(10944)

BUGTRAQ - 20021227 Buffer overflow in PHP "wordwrap" function

GENTOO - 200301-8

REDHAT - RHSA-2003:017

SUSE - SuSE-SA:2003:0009

MANDRAKE - MDKSA-2003:019

ENGARDE - ESA-20030219-003


Last Updated: 27 May 2016 10:37:18