{"cves":[{"id":"CVE-2007-4668","published":"2007-09-04T22:17:00","updated_at":"2025-07-17T16:42:09.648205+00:00","description":"\nUnspecified vulnerability in the server in Firebird before 2.0.2 allows\nremote attackers to determine the existence of arbitrary files, and\npossibly obtain other \"file access,\" via unknown vectors, aka CORE-1312.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4668"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firebird2.0","source":"https://ubuntu.com/security/cve?package=firebird2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firebird2.0","debian":"https://tracker.debian.org/pkg/firebird2.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4667","published":"2007-09-04T22:17:00","updated_at":"2025-07-17T16:42:09.648205+00:00","description":"\nUnspecified vulnerability in the Services API in Firebird before 2.0.2\nallows remote attackers to cause a denial of service, aka CORE-1149.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4667"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firebird2.0","source":"https://ubuntu.com/security/cve?package=firebird2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firebird2.0","debian":"https://tracker.debian.org/pkg/firebird2.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4666","published":"2007-09-04T22:17:00","updated_at":"2025-07-17T16:42:09.648205+00:00","description":"\nUnspecified vulnerability in the server in Firebird before 2.0.2, when a\nSuperserver/TCP/IP environment is configured, allows remote attackers to\ncause a denial of service (CPU and memory consumption) via \"large network\npackets with garbage\", aka CORE-1397.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4666"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firebird2.0","source":"https://ubuntu.com/security/cve?package=firebird2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firebird2.0","debian":"https://tracker.debian.org/pkg/firebird2.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4665","published":"2007-09-04T22:17:00","updated_at":"2025-07-17T16:42:09.648205+00:00","description":"\nUnspecified vulnerability in the server in Firebird before 2.0.2 allows\nremote attackers to cause a denial of service (daemon crash) via an XNET\nsession that makes multiple simultaneous requests to register events, aka\nCORE-1403.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4665"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firebird2.0","source":"https://ubuntu.com/security/cve?package=firebird2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firebird2.0","debian":"https://tracker.debian.org/pkg/firebird2.0","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4664","published":"2007-09-04T22:17:00","updated_at":"2025-07-17T16:42:07.980881+00:00","description":"\nUnspecified vulnerability in the (1) attach database and (2) create\ndatabase functionality in Firebird before 2.0.2, when a filename exceeds\nMAX_PATH_LEN, has unknown impact and attack vectors, aka CORE-1405.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4664"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firebird2.0","source":"https://ubuntu.com/security/cve?package=firebird2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firebird2.0","debian":"https://tracker.debian.org/pkg/firebird2.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4663","published":"2007-09-04T22:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDirectory traversal vulnerability in PHP before 5.2.4 allows attackers to\nbypass open_basedir restrictions via unspecified vectors involving the glob\nfunction.","ubuntu_description":"","notes":[{"author":"kees","note":"open_basedir not supported"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4663"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"feisty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.4","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4662","published":"2007-09-04T22:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the php_openssl_make_REQ function in PHP before 5.2.4\nhas unknown impact and attack vectors.","ubuntu_description":"","notes":[{"author":"kees","note":"http://cvs.php.net/viewcvs.cgi/php-src/ext/openssl/openssl.c?r1=1.146&r2=1.147\nupstream is wrong: should be 199 not 200.\n203-openssl_make_REQ-overflow.patch"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-549-1","https://www.cve.org/CVERecord?id=CVE-2007-4662"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.10","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.6-1ubuntu2.7","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"5.2.3-1ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.4","component":null,"pocket":"security"}]}],"notices_ids":["USN-549-1"],"notices":[{"id":"USN-549-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2007-11-29T22:38:09.391050","description":"It was discovered that the wordwrap function did not correctly\ncheck lengths. Remote attackers could exploit this to cause\na crash or monopolize CPU resources, resulting in a denial of\nservice. (CVE-2007-3998)\n\nInteger overflows were discovered in the strspn and strcspn functions.\nAttackers could exploit this to read arbitrary areas of memory, possibly\ngaining access to sensitive information. (CVE-2007-4657)\n\nStanislav Malyshev discovered that money_format function did not correctly\nhandle certain tokens. If a PHP application were tricked into processing\na bad format string, a remote attacker could execute arbitrary code with\napplication privileges. (CVE-2007-4658)\n\nIt was discovered that the php_openssl_make_REQ function did not\ncorrectly check buffer lengths. A remote attacker could send a\nspecially crafted message and execute arbitrary code with application\nprivileges. (CVE-2007-4662)\n\nIt was discovered that certain characters in session cookies were not\nhandled correctly. A remote attacker could injection values which could\nlead to altered application behavior, potentially gaining additional\nprivileges. (CVE-2007-3799)\n\nGerhard Wagner discovered that the chunk_split function did not\ncorrectly handle long strings. A remote attacker could exploit this\nto execute arbitrary code with application privileges. (CVE-2007-2872,\nCVE-2007-4660, CVE-2007-4661)\n\nStefan Esser discovered that deeply nested arrays could be made to\nfill stack space. A remote attacker could exploit this to cause a\ncrash or monopolize CPU resources, resulting in a denial of service.\n(CVE-2007-1285, CVE-2007-4670)\n\nRasmus Lerdorf discovered that the htmlentities and htmlspecialchars\nfunctions did not correctly stop when handling partial multibyte\nsequences. A remote attacker could exploit this to read certain areas of\nmemory, possibly gaining access to sensitive information. (CVE-2007-5898)\n\nIt was discovered that the output_add_rewrite_var fucntion would\nsometimes leak session id information to forms targeting remote URLs.\nMalicious remote sites could use this information to gain access to a\nPHP application user's login credentials. (CVE-2007-5899)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"php5","version":"5.2.3-1ubuntu6.1","description":"","is_source":true},{"name":"php5-cli","version":"5.2.3-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.1"},{"name":"php5-cgi","version":"5.2.3-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.1"},{"name":"libapache2-mod-php5","version":"5.2.3-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.1"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.10","description":"","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.10"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.10"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.10"}],"feisty":[{"name":"php5","version":"5.2.1-0ubuntu1.5","description":"","is_source":true},{"name":"php5-cli","version":"5.2.1-0ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.5"},{"name":"php5-cgi","version":"5.2.1-0ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.5"},{"name":"libapache2-mod-php5","version":"5.2.1-0ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.5"}],"edgy":[{"name":"php5","version":"5.1.6-1ubuntu2.7","description":"","is_source":true},{"name":"php5-cli","version":"5.1.6-1ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.6-1ubuntu2.7"},{"name":"php5-cgi","version":"5.1.6-1ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.6-1ubuntu2.7"},{"name":"libapache2-mod-php5","version":"5.1.6-1ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.6-1ubuntu2.7"}]},"type":"USN","cves_ids":["CVE-2007-1285","CVE-2007-2872","CVE-2007-3799","CVE-2007-3998","CVE-2007-4657","CVE-2007-4658","CVE-2007-4660","CVE-2007-4661","CVE-2007-4662","CVE-2007-4670","CVE-2007-5898","CVE-2007-5899"]}]},{"id":"CVE-2007-4661","published":"2007-09-04T22:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe chunk_split function in string.c in PHP 5.2.3 does not properly\ncalculate the needed buffer size due to precision loss when performing\ninteger arithmetic with floating point numbers, which has unknown attack\nvectors and impact, possibly resulting in a heap-based buffer overflow.\nNOTE: this is due to an incomplete fix for CVE-2007-2872.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-549-1","https://www.cve.org/CVERecord?id=CVE-2007-4661"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.10","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.6-1ubuntu2.7","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"5.2.3-1ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.4","component":null,"pocket":"security"}]}],"notices_ids":["USN-549-1"],"notices":[{"id":"USN-549-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2007-11-29T22:38:09.391050","description":"It was discovered that the wordwrap function did not correctly\ncheck lengths. Remote attackers could exploit this to cause\na crash or monopolize CPU resources, resulting in a denial of\nservice. (CVE-2007-3998)\n\nInteger overflows were discovered in the strspn and strcspn functions.\nAttackers could exploit this to read arbitrary areas of memory, possibly\ngaining access to sensitive information. (CVE-2007-4657)\n\nStanislav Malyshev discovered that money_format function did not correctly\nhandle certain tokens. If a PHP application were tricked into processing\na bad format string, a remote attacker could execute arbitrary code with\napplication privileges. (CVE-2007-4658)\n\nIt was discovered that the php_openssl_make_REQ function did not\ncorrectly check buffer lengths. A remote attacker could send a\nspecially crafted message and execute arbitrary code with application\nprivileges. (CVE-2007-4662)\n\nIt was discovered that certain characters in session cookies were not\nhandled correctly. A remote attacker could injection values which could\nlead to altered application behavior, potentially gaining additional\nprivileges. (CVE-2007-3799)\n\nGerhard Wagner discovered that the chunk_split function did not\ncorrectly handle long strings. A remote attacker could exploit this\nto execute arbitrary code with application privileges. (CVE-2007-2872,\nCVE-2007-4660, CVE-2007-4661)\n\nStefan Esser discovered that deeply nested arrays could be made to\nfill stack space. A remote attacker could exploit this to cause a\ncrash or monopolize CPU resources, resulting in a denial of service.\n(CVE-2007-1285, CVE-2007-4670)\n\nRasmus Lerdorf discovered that the htmlentities and htmlspecialchars\nfunctions did not correctly stop when handling partial multibyte\nsequences. A remote attacker could exploit this to read certain areas of\nmemory, possibly gaining access to sensitive information. (CVE-2007-5898)\n\nIt was discovered that the output_add_rewrite_var fucntion would\nsometimes leak session id information to forms targeting remote URLs.\nMalicious remote sites could use this information to gain access to a\nPHP application user's login credentials. (CVE-2007-5899)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"php5","version":"5.2.3-1ubuntu6.1","description":"","is_source":true},{"name":"php5-cli","version":"5.2.3-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.1"},{"name":"php5-cgi","version":"5.2.3-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.1"},{"name":"libapache2-mod-php5","version":"5.2.3-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.1"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.10","description":"","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.10"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.10"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.10"}],"feisty":[{"name":"php5","version":"5.2.1-0ubuntu1.5","description":"","is_source":true},{"name":"php5-cli","version":"5.2.1-0ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.5"},{"name":"php5-cgi","version":"5.2.1-0ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.5"},{"name":"libapache2-mod-php5","version":"5.2.1-0ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.5"}],"edgy":[{"name":"php5","version":"5.1.6-1ubuntu2.7","description":"","is_source":true},{"name":"php5-cli","version":"5.1.6-1ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.6-1ubuntu2.7"},{"name":"php5-cgi","version":"5.1.6-1ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.6-1ubuntu2.7"},{"name":"libapache2-mod-php5","version":"5.1.6-1ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.6-1ubuntu2.7"}]},"type":"USN","cves_ids":["CVE-2007-1285","CVE-2007-2872","CVE-2007-3799","CVE-2007-3998","CVE-2007-4657","CVE-2007-4658","CVE-2007-4660","CVE-2007-4661","CVE-2007-4662","CVE-2007-4670","CVE-2007-5898","CVE-2007-5899"]}]},{"id":"CVE-2007-4660","published":"2007-09-04T22:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the chunk_split function in PHP before 5.2.4\nhas unknown impact and attack vectors, related to an incorrect size\ncalculation.","ubuntu_description":"","notes":[{"author":"kees","note":"fixed with CVE-2007-4657"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-549-1","https://www.cve.org/CVERecord?id=CVE-2007-4660"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.10","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.6-1ubuntu2.7","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"5.2.3-1ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.4","component":null,"pocket":"security"}]}],"notices_ids":["USN-549-1"],"notices":[{"id":"USN-549-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2007-11-29T22:38:09.391050","description":"It was discovered that the wordwrap function did not correctly\ncheck lengths. Remote attackers could exploit this to cause\na crash or monopolize CPU resources, resulting in a denial of\nservice. (CVE-2007-3998)\n\nInteger overflows were discovered in the strspn and strcspn functions.\nAttackers could exploit this to read arbitrary areas of memory, possibly\ngaining access to sensitive information. (CVE-2007-4657)\n\nStanislav Malyshev discovered that money_format function did not correctly\nhandle certain tokens. If a PHP application were tricked into processing\na bad format string, a remote attacker could execute arbitrary code with\napplication privileges. (CVE-2007-4658)\n\nIt was discovered that the php_openssl_make_REQ function did not\ncorrectly check buffer lengths. A remote attacker could send a\nspecially crafted message and execute arbitrary code with application\nprivileges. (CVE-2007-4662)\n\nIt was discovered that certain characters in session cookies were not\nhandled correctly. A remote attacker could injection values which could\nlead to altered application behavior, potentially gaining additional\nprivileges. (CVE-2007-3799)\n\nGerhard Wagner discovered that the chunk_split function did not\ncorrectly handle long strings. A remote attacker could exploit this\nto execute arbitrary code with application privileges. (CVE-2007-2872,\nCVE-2007-4660, CVE-2007-4661)\n\nStefan Esser discovered that deeply nested arrays could be made to\nfill stack space. A remote attacker could exploit this to cause a\ncrash or monopolize CPU resources, resulting in a denial of service.\n(CVE-2007-1285, CVE-2007-4670)\n\nRasmus Lerdorf discovered that the htmlentities and htmlspecialchars\nfunctions did not correctly stop when handling partial multibyte\nsequences. A remote attacker could exploit this to read certain areas of\nmemory, possibly gaining access to sensitive information. (CVE-2007-5898)\n\nIt was discovered that the output_add_rewrite_var fucntion would\nsometimes leak session id information to forms targeting remote URLs.\nMalicious remote sites could use this information to gain access to a\nPHP application user's login credentials. (CVE-2007-5899)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"php5","version":"5.2.3-1ubuntu6.1","description":"","is_source":true},{"name":"php5-cli","version":"5.2.3-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.1"},{"name":"php5-cgi","version":"5.2.3-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.1"},{"name":"libapache2-mod-php5","version":"5.2.3-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.1"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.10","description":"","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.10"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.10"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.10"}],"feisty":[{"name":"php5","version":"5.2.1-0ubuntu1.5","description":"","is_source":true},{"name":"php5-cli","version":"5.2.1-0ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.5"},{"name":"php5-cgi","version":"5.2.1-0ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.5"},{"name":"libapache2-mod-php5","version":"5.2.1-0ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.5"}],"edgy":[{"name":"php5","version":"5.1.6-1ubuntu2.7","description":"","is_source":true},{"name":"php5-cli","version":"5.1.6-1ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.6-1ubuntu2.7"},{"name":"php5-cgi","version":"5.1.6-1ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.6-1ubuntu2.7"},{"name":"libapache2-mod-php5","version":"5.1.6-1ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.6-1ubuntu2.7"}]},"type":"USN","cves_ids":["CVE-2007-1285","CVE-2007-2872","CVE-2007-3799","CVE-2007-3998","CVE-2007-4657","CVE-2007-4658","CVE-2007-4660","CVE-2007-4661","CVE-2007-4662","CVE-2007-4670","CVE-2007-5898","CVE-2007-5899"]}]},{"id":"CVE-2007-4659","published":"2007-09-04T22:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe zend_alter_ini_entry function in PHP before 5.2.4 does not properly\nhandle an interruption to the flow of execution triggered by a memory_limit\nviolation, which has unknown impact and attack vectors.","ubuntu_description":"","notes":[{"author":"kees","note":"205-zend_alter_ini_entry-fix.patch seems to break commandline ini config"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4659"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4658","published":"2007-09-04T22:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe money_format function in PHP 5 before 5.2.4, and PHP 4 before 4.4.8,\npermits multiple (1) %i and (2) %n tokens, which has unknown impact and\nattack vectors, possibly related to a format string vulnerability.","ubuntu_description":"","notes":[{"author":"kees","note":"from Line 7667, http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/string.c?r1=1.640&r2=1.641\n202-money-format-abuse.patch"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-549-1","https://www.cve.org/CVERecord?id=CVE-2007-4658"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.10","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.6-1ubuntu2.7","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"5.2.3-1ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.4","component":null,"pocket":"security"}]}],"notices_ids":["USN-549-1"],"notices":[{"id":"USN-549-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2007-11-29T22:38:09.391050","description":"It was discovered that the wordwrap function did not correctly\ncheck lengths. Remote attackers could exploit this to cause\na crash or monopolize CPU resources, resulting in a denial of\nservice. (CVE-2007-3998)\n\nInteger overflows were discovered in the strspn and strcspn functions.\nAttackers could exploit this to read arbitrary areas of memory, possibly\ngaining access to sensitive information. (CVE-2007-4657)\n\nStanislav Malyshev discovered that money_format function did not correctly\nhandle certain tokens. If a PHP application were tricked into processing\na bad format string, a remote attacker could execute arbitrary code with\napplication privileges. (CVE-2007-4658)\n\nIt was discovered that the php_openssl_make_REQ function did not\ncorrectly check buffer lengths. A remote attacker could send a\nspecially crafted message and execute arbitrary code with application\nprivileges. (CVE-2007-4662)\n\nIt was discovered that certain characters in session cookies were not\nhandled correctly. A remote attacker could injection values which could\nlead to altered application behavior, potentially gaining additional\nprivileges. (CVE-2007-3799)\n\nGerhard Wagner discovered that the chunk_split function did not\ncorrectly handle long strings. A remote attacker could exploit this\nto execute arbitrary code with application privileges. (CVE-2007-2872,\nCVE-2007-4660, CVE-2007-4661)\n\nStefan Esser discovered that deeply nested arrays could be made to\nfill stack space. A remote attacker could exploit this to cause a\ncrash or monopolize CPU resources, resulting in a denial of service.\n(CVE-2007-1285, CVE-2007-4670)\n\nRasmus Lerdorf discovered that the htmlentities and htmlspecialchars\nfunctions did not correctly stop when handling partial multibyte\nsequences. A remote attacker could exploit this to read certain areas of\nmemory, possibly gaining access to sensitive information. (CVE-2007-5898)\n\nIt was discovered that the output_add_rewrite_var fucntion would\nsometimes leak session id information to forms targeting remote URLs.\nMalicious remote sites could use this information to gain access to a\nPHP application user's login credentials. (CVE-2007-5899)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"php5","version":"5.2.3-1ubuntu6.1","description":"","is_source":true},{"name":"php5-cli","version":"5.2.3-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.1"},{"name":"php5-cgi","version":"5.2.3-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.1"},{"name":"libapache2-mod-php5","version":"5.2.3-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.1"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.10","description":"","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.10"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.10"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.10"}],"feisty":[{"name":"php5","version":"5.2.1-0ubuntu1.5","description":"","is_source":true},{"name":"php5-cli","version":"5.2.1-0ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.5"},{"name":"php5-cgi","version":"5.2.1-0ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.5"},{"name":"libapache2-mod-php5","version":"5.2.1-0ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.5"}],"edgy":[{"name":"php5","version":"5.1.6-1ubuntu2.7","description":"","is_source":true},{"name":"php5-cli","version":"5.1.6-1ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.6-1ubuntu2.7"},{"name":"php5-cgi","version":"5.1.6-1ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.6-1ubuntu2.7"},{"name":"libapache2-mod-php5","version":"5.1.6-1ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.6-1ubuntu2.7"}]},"type":"USN","cves_ids":["CVE-2007-1285","CVE-2007-2872","CVE-2007-3799","CVE-2007-3998","CVE-2007-4657","CVE-2007-4658","CVE-2007-4660","CVE-2007-4661","CVE-2007-4662","CVE-2007-4670","CVE-2007-5898","CVE-2007-5899"]}]},{"id":"CVE-2007-4656","published":"2007-09-04T22:17:00","updated_at":"2025-07-17T16:42:07.980881+00:00","description":"\nbackup-manager-upload in Backup Manager before 0.6.3 provides the FTP\nserver hostname, username, and password as plaintext command line arguments\nduring FTP uploads, which allows local users to obtain sensitive\ninformation by listing the process and its arguments, a different\nvulnerability than CVE-2007-2766.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4656"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"backup-manager","source":"https://ubuntu.com/security/cve?package=backup-manager","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=backup-manager","debian":"https://tracker.debian.org/pkg/backup-manager","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.7.6-3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"0.7.6-3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.7.6-3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.7.6-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4652","published":"2007-09-04T19:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe session extension in PHP before 5.2.4 might allow local users to bypass\nopen_basedir restrictions via a session file that is a symlink.","ubuntu_description":"","notes":[{"author":"kees","note":"open_basedir not supported"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4652"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"5.2.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3997","published":"2007-09-04T18:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP 5\nbefore 5.2.4, allow remote attackers to bypass safe_mode and open_basedir\nrestrictions via MySQL LOCAL INFILE operations, as demonstrated by a query\nwith LOAD DATA LOCAL INFILE.","ubuntu_description":"","notes":[{"author":"kees","note":"safe_mode/open_basedir not supported"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-3997"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php4","source":"https://ubuntu.com/security/cve?package=php4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php4","debian":"https://tracker.debian.org/pkg/php4","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4.8","component":null,"pocket":"security"}]},{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3996","published":"2007-09-04T18:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple integer overflows in libgd in PHP before 5.2.4 allow remote\nattackers to cause a denial of service (application crash) and possibly\nexecute arbitrary code via a large (1) srcW or (2) srcH value to the (a)\ngdImageCopyResized function, or a large (3) sy (height) or (4) sx (width)\nvalue to the (b) gdImageCreate or the (c) gdImageCreateTrueColor function.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"note this is gdImageCreate and gdImageCreateTrueColor\ndapper-gutsy libgd2 are affected to varying degrees\nphp5-gd segfaults on feisty and gutsy before patching libgd2,\nand dapper-gutsy segfault after (this is because feisty-gutsy had a partial\nfix already in libgd2). php5-gd is not handling the error condition when\nlibgd2 fails properly. Verified that 5.2.4 works with patched libgd2."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.secweb.se/en/advisories/php-imagecreatetruecolor-integer-overflow/","https://ubuntu.com/security/notices/USN-557-1","https://ubuntu.com/security/notices/USN-720-1","https://www.cve.org/CVERecord?id=CVE-2007-3996"],"bugs":[""],"patches":{"php5":["vendor: http://www.mandriva.com/security/advisories?name=MDKSA-2007:187","upstream: http://cvs.php.net/viewvc.cgi/php-src/ext/gd/gd.c?r1=1.312.2.20.2.28&r2=1.312.2.20.2.29"]},"tags":{},"packages":[{"name":"libgd2","source":"https://ubuntu.com/security/cve?package=libgd2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libgd2","debian":"https://tracker.debian.org/pkg/libgd2","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.33-2ubuntu5.3","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.33-4ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.34~rc1-2ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.34-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"2.0.35.dfsg-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"2.0.35.dfsg-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.35","component":null,"pocket":"security"}]},{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.13","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"5.2.3-1ubuntu6.5","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"5.2.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"5.2.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.4","component":null,"pocket":"security"}]}],"notices_ids":["USN-557-1","USN-720-1"],"notices":[{"id":"USN-557-1","title":"GD library vulnerability","summary":"GD library vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2007-12-18T23:39:16.170071","description":"Mattias Bengtsson and Philip Olausson discovered that the GD\nlibrary did not properly perform bounds checking when creating\nimages. An attacker could send specially crafted input to\napplications linked against libgd2 and cause a denial of service\nor possibly execute arbitrary code.\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"libgd2","version":"2.0.34-1ubuntu1.1","description":"","is_source":true},{"name":"libgd2-xpm","version":"2.0.34-1ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libgd2","version_link":"https://launchpad.net/ubuntu/+source/libgd2/2.0.34-1ubuntu1.1"},{"name":"libgd2-noxpm","version":"2.0.34-1ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libgd2","version_link":"https://launchpad.net/ubuntu/+source/libgd2/2.0.34-1ubuntu1.1"}],"dapper":[{"name":"libgd2","version":"2.0.33-2ubuntu5.3","description":"","is_source":true},{"name":"libgd2-xpm","version":"2.0.33-2ubuntu5.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libgd2","version_link":"https://launchpad.net/ubuntu/+source/libgd2/2.0.33-2ubuntu5.3"},{"name":"libgd2-noxpm","version":"2.0.33-2ubuntu5.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libgd2","version_link":"https://launchpad.net/ubuntu/+source/libgd2/2.0.33-2ubuntu5.3"}],"feisty":[{"name":"libgd2","version":"2.0.34~rc1-2ubuntu1.2","description":"","is_source":true},{"name":"libgd2-xpm","version":"2.0.34~rc1-2ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libgd2","version_link":"https://launchpad.net/ubuntu/+source/libgd2/2.0.34~rc1-2ubuntu1.2"},{"name":"libgd2-noxpm","version":"2.0.34~rc1-2ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libgd2","version_link":"https://launchpad.net/ubuntu/+source/libgd2/2.0.34~rc1-2ubuntu1.2"}],"edgy":[{"name":"libgd2","version":"2.0.33-4ubuntu2.2","description":"","is_source":true},{"name":"libgd2-xpm","version":"2.0.33-4ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libgd2","version_link":"https://launchpad.net/ubuntu/+source/libgd2/2.0.33-4ubuntu2.2"},{"name":"libgd2-noxpm","version":"2.0.33-4ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libgd2","version_link":"https://launchpad.net/ubuntu/+source/libgd2/2.0.33-4ubuntu2.2"}]},"type":"USN","cves_ids":["CVE-2007-3996"]},{"id":"USN-720-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-02-12T19:13:44.913639","description":"It was discovered that PHP did not properly enforce php_admin_value and\nphp_admin_flag restrictions in the Apache configuration file. A local attacker\ncould create a specially crafted PHP script that would bypass intended security\nrestrictions. This issue only applied to Ubuntu 6.06 LTS, 7.10, and 8.04 LTS.\n(CVE-2007-5900)\n\nIt was discovered that PHP did not correctly handle certain malformed font\nfiles. If a PHP application were tricked into processing a specially crafted\nfont file, an attacker may be able to cause a denial of service and possibly\nexecute arbitrary code with application privileges. (CVE-2008-3658)\n\nIt was discovered that PHP did not properly check the delimiter argument to the\nexplode function. If a script passed untrusted input to the explode function, an\nattacker could cause a denial of service and possibly execute arbitrary code\nwith application privileges. (CVE-2008-3659) \n\nIt was discovered that PHP, when used as FastCGI module, did not properly\nsanitize requests. By performing a request with multiple dots preceding the\nextension, an attacker could cause a denial of service. (CVE-2008-3660)\n\nIt was discovered that PHP did not properly handle Unicode conversion in the\nmbstring extension. If a PHP application were tricked into processing a\nspecially crafted string containing an HTML entity, an attacker could execute\narbitrary code with application privileges. (CVE-2008-5557)\n\nIt was discovered that PHP did not properly initialize the page_uid and page_gid\nglobal variables for use by the SAPI php_getuid function. An attacker could\nexploit this issue to bypass safe_mode restrictions. (CVE-2008-5624)\n\nIt was dicovered that PHP did not properly enforce error_log safe_mode\nrestrictions when set by php_admin_flag in the Apache configuration file. A\nlocal attacker could create a specially crafted PHP script that would overwrite\narbitrary files. (CVE-2008-5625)\n\nIt was discovered that PHP contained a flaw in the ZipArchive::extractTo\nfunction. If a PHP application were tricked into processing a specially crafted\nzip file that had filenames containing \"..\", an attacker could write arbitrary\nfiles within the filesystem. This issue only applied to Ubuntu 7.10, 8.04 LTS,\nand 8.10. (CVE-2008-5658)\n\nUSN-557-1 fixed a vulnerability in the GD library. When using the GD library,\nPHP did not properly handle the return codes that were added in the security\nupdate. An attacker could exploit this issue with a specially crafted image file\nand cause PHP to crash, leading to a denial of service. This issue only applied\nto Ubuntu 6.06 LTS, and 7.10. (CVE-2007-3996)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"php5","version":"5.2.3-1ubuntu6.5","description":"","is_source":true},{"name":"php5-cli","version":"5.2.3-1ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.5"},{"name":"php5-cgi","version":"5.2.3-1ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.5"},{"name":"php5-gd","version":"5.2.3-1ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.5"},{"name":"libapache2-mod-php5","version":"5.2.3-1ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.5"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.13","description":"","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.13"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.13"},{"name":"php5-gd","version":"5.1.2-1ubuntu3.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.13"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.13"}],"intrepid":[{"name":"php5","version":"5.2.6-2ubuntu4.1","description":"","is_source":true},{"name":"php5-cli","version":"5.2.6-2ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6-2ubuntu4.1"},{"name":"php5-cgi","version":"5.2.6-2ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6-2ubuntu4.1"},{"name":"php5-gd","version":"5.2.6-2ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6-2ubuntu4.1"},{"name":"libapache2-mod-php5","version":"5.2.6-2ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6-2ubuntu4.1"},{"name":"libapache2-mod-php5filter","version":"5.2.6-2ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6-2ubuntu4.1"}],"hardy":[{"name":"php5","version":"5.2.4-2ubuntu5.5","description":"","is_source":true},{"name":"php5-cli","version":"5.2.4-2ubuntu5.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.5"},{"name":"php5-cgi","version":"5.2.4-2ubuntu5.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.5"},{"name":"php5-gd","version":"5.2.4-2ubuntu5.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.5"},{"name":"libapache2-mod-php5","version":"5.2.4-2ubuntu5.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.5"}]},"type":"USN","cves_ids":["CVE-2008-3659","CVE-2007-5900","CVE-2007-3996","CVE-2008-5625","CVE-2008-5624","CVE-2008-5557","CVE-2008-3658","CVE-2008-3660","CVE-2008-5658"]}]},{"id":"CVE-2007-4650","published":"2007-09-04T17:17:00","updated_at":"2025-07-17T16:42:07.980881+00:00","description":"\nMultiple unspecified vulnerabilities in Gallery before 2.2.3 allow\nattackers to (1) rename items, (2) read and modify item properties, or (3)\nlock and replace items via unknown vectors in (a) the WebDAV module; and\n(4) edit unspecified data files using \"linked items\" in WebDAV and (b)\nReupload modules.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4650"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/gallery2/+bug/163492"],"patches":{},"tags":{},"packages":[{"name":"gallery2","source":"https://ubuntu.com/security/cve?package=gallery2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gallery2","debian":"https://tracker.debian.org/pkg/gallery2","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4657","published":"2007-09-04T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4,\nallow remote attackers to obtain sensitive information (memory contents) or\ncause a denial of service (thread crash) via a large len value to the (1)\nstrspn or (2) strcspn function, which triggers an out-of-bounds read.\nNOTE: this affects different product versions than CVE-2007-3996.","ubuntu_description":"","notes":[{"author":"kees","note":"http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/string.c?r1=1.640&r2=1.641, prior to line 7667\n201-strspn-oob-read.patch"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-549-1","https://www.cve.org/CVERecord?id=CVE-2007-4657"],"bugs":[""],"patches":{"php4":["upstream: http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/string.c?r1=1.640&r2=1.641, prior to line 7667","other: 201-strspn-oob-read.patch"]},"tags":{},"packages":[{"name":"php4","source":"https://ubuntu.com/security/cve?package=php4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php4","debian":"https://tracker.debian.org/pkg/php4","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4.8","component":null,"pocket":"security"}]},{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.10","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.6-1ubuntu2.7","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"5.2.3-1ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"5.2.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"5.2.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"5.2.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"5.2.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.4","component":null,"pocket":"security"}]}],"notices_ids":["USN-549-1"],"notices":[{"id":"USN-549-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2007-11-29T22:38:09.391050","description":"It was discovered that the wordwrap function did not correctly\ncheck lengths. Remote attackers could exploit this to cause\na crash or monopolize CPU resources, resulting in a denial of\nservice. (CVE-2007-3998)\n\nInteger overflows were discovered in the strspn and strcspn functions.\nAttackers could exploit this to read arbitrary areas of memory, possibly\ngaining access to sensitive information. (CVE-2007-4657)\n\nStanislav Malyshev discovered that money_format function did not correctly\nhandle certain tokens. If a PHP application were tricked into processing\na bad format string, a remote attacker could execute arbitrary code with\napplication privileges. (CVE-2007-4658)\n\nIt was discovered that the php_openssl_make_REQ function did not\ncorrectly check buffer lengths. A remote attacker could send a\nspecially crafted message and execute arbitrary code with application\nprivileges. (CVE-2007-4662)\n\nIt was discovered that certain characters in session cookies were not\nhandled correctly. A remote attacker could injection values which could\nlead to altered application behavior, potentially gaining additional\nprivileges. (CVE-2007-3799)\n\nGerhard Wagner discovered that the chunk_split function did not\ncorrectly handle long strings. A remote attacker could exploit this\nto execute arbitrary code with application privileges. (CVE-2007-2872,\nCVE-2007-4660, CVE-2007-4661)\n\nStefan Esser discovered that deeply nested arrays could be made to\nfill stack space. A remote attacker could exploit this to cause a\ncrash or monopolize CPU resources, resulting in a denial of service.\n(CVE-2007-1285, CVE-2007-4670)\n\nRasmus Lerdorf discovered that the htmlentities and htmlspecialchars\nfunctions did not correctly stop when handling partial multibyte\nsequences. A remote attacker could exploit this to read certain areas of\nmemory, possibly gaining access to sensitive information. (CVE-2007-5898)\n\nIt was discovered that the output_add_rewrite_var fucntion would\nsometimes leak session id information to forms targeting remote URLs.\nMalicious remote sites could use this information to gain access to a\nPHP application user's login credentials. (CVE-2007-5899)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"php5","version":"5.2.3-1ubuntu6.1","description":"","is_source":true},{"name":"php5-cli","version":"5.2.3-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.1"},{"name":"php5-cgi","version":"5.2.3-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.1"},{"name":"libapache2-mod-php5","version":"5.2.3-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.1"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.10","description":"","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.10"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.10"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.10"}],"feisty":[{"name":"php5","version":"5.2.1-0ubuntu1.5","description":"","is_source":true},{"name":"php5-cli","version":"5.2.1-0ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.5"},{"name":"php5-cgi","version":"5.2.1-0ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.5"},{"name":"libapache2-mod-php5","version":"5.2.1-0ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.5"}],"edgy":[{"name":"php5","version":"5.1.6-1ubuntu2.7","description":"","is_source":true},{"name":"php5-cli","version":"5.1.6-1ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.6-1ubuntu2.7"},{"name":"php5-cgi","version":"5.1.6-1ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.6-1ubuntu2.7"},{"name":"libapache2-mod-php5","version":"5.1.6-1ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.6-1ubuntu2.7"}]},"type":"USN","cves_ids":["CVE-2007-1285","CVE-2007-2872","CVE-2007-3799","CVE-2007-3998","CVE-2007-4657","CVE-2007-4658","CVE-2007-4660","CVE-2007-4661","CVE-2007-4662","CVE-2007-4670","CVE-2007-5898","CVE-2007-5899"]}]},{"id":"CVE-2007-3998","published":"2007-09-04T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe wordwrap function in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, does\nnot properly use the breakcharlen variable, which allows remote attackers\nto cause a denial of service (divide-by-zero error and application crash,\nor infinite loop) via certain arguments, as demonstrated by a 'chr(0), 0,\n\"\"' argument set.","ubuntu_description":"","notes":[{"author":"kees","note":"http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/string.c?r1=1.445.2.14.2.63&r2=1.445.2.14.2.64&view=patch\n200-string-wordwrap.patch"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-549-1","https://www.cve.org/CVERecord?id=CVE-2007-3998"],"bugs":[""],"patches":{"php4":["upstream: http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/string.c?r1=1.445.2.14.2.63&r2=1.445.2.14.2.64&view=patch","other: 200-string-wordwrap.patch"]},"tags":{},"packages":[{"name":"php4","source":"https://ubuntu.com/security/cve?package=php4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php4","debian":"https://tracker.debian.org/pkg/php4","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4.8","component":null,"pocket":"security"}]},{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.10","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.6-1ubuntu2.7","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"5.2.3-1ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"5.2.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"5.2.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"5.2.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"5.2.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.4","component":null,"pocket":"security"}]}],"notices_ids":["USN-549-1"],"notices":[{"id":"USN-549-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2007-11-29T22:38:09.391050","description":"It was discovered that the wordwrap function did not correctly\ncheck lengths. Remote attackers could exploit this to cause\na crash or monopolize CPU resources, resulting in a denial of\nservice. (CVE-2007-3998)\n\nInteger overflows were discovered in the strspn and strcspn functions.\nAttackers could exploit this to read arbitrary areas of memory, possibly\ngaining access to sensitive information. (CVE-2007-4657)\n\nStanislav Malyshev discovered that money_format function did not correctly\nhandle certain tokens. If a PHP application were tricked into processing\na bad format string, a remote attacker could execute arbitrary code with\napplication privileges. (CVE-2007-4658)\n\nIt was discovered that the php_openssl_make_REQ function did not\ncorrectly check buffer lengths. A remote attacker could send a\nspecially crafted message and execute arbitrary code with application\nprivileges. (CVE-2007-4662)\n\nIt was discovered that certain characters in session cookies were not\nhandled correctly. A remote attacker could injection values which could\nlead to altered application behavior, potentially gaining additional\nprivileges. (CVE-2007-3799)\n\nGerhard Wagner discovered that the chunk_split function did not\ncorrectly handle long strings. A remote attacker could exploit this\nto execute arbitrary code with application privileges. (CVE-2007-2872,\nCVE-2007-4660, CVE-2007-4661)\n\nStefan Esser discovered that deeply nested arrays could be made to\nfill stack space. A remote attacker could exploit this to cause a\ncrash or monopolize CPU resources, resulting in a denial of service.\n(CVE-2007-1285, CVE-2007-4670)\n\nRasmus Lerdorf discovered that the htmlentities and htmlspecialchars\nfunctions did not correctly stop when handling partial multibyte\nsequences. A remote attacker could exploit this to read certain areas of\nmemory, possibly gaining access to sensitive information. (CVE-2007-5898)\n\nIt was discovered that the output_add_rewrite_var fucntion would\nsometimes leak session id information to forms targeting remote URLs.\nMalicious remote sites could use this information to gain access to a\nPHP application user's login credentials. (CVE-2007-5899)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"php5","version":"5.2.3-1ubuntu6.1","description":"","is_source":true},{"name":"php5-cli","version":"5.2.3-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.1"},{"name":"php5-cgi","version":"5.2.3-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.1"},{"name":"libapache2-mod-php5","version":"5.2.3-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.1"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.10","description":"","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.10"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.10"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.10"}],"feisty":[{"name":"php5","version":"5.2.1-0ubuntu1.5","description":"","is_source":true},{"name":"php5-cli","version":"5.2.1-0ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.5"},{"name":"php5-cgi","version":"5.2.1-0ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.5"},{"name":"libapache2-mod-php5","version":"5.2.1-0ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.5"}],"edgy":[{"name":"php5","version":"5.1.6-1ubuntu2.7","description":"","is_source":true},{"name":"php5-cli","version":"5.1.6-1ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.6-1ubuntu2.7"},{"name":"php5-cgi","version":"5.1.6-1ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.6-1ubuntu2.7"},{"name":"libapache2-mod-php5","version":"5.1.6-1ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.6-1ubuntu2.7"}]},"type":"USN","cves_ids":["CVE-2007-1285","CVE-2007-2872","CVE-2007-3799","CVE-2007-3998","CVE-2007-4657","CVE-2007-4658","CVE-2007-4660","CVE-2007-4661","CVE-2007-4662","CVE-2007-4670","CVE-2007-5898","CVE-2007-5899"]}]},{"id":"CVE-2007-4631","published":"2007-08-31T22:17:00","updated_at":"2025-07-17T16:42:07.980881+00:00","description":"\nThe DataLoader::doStart function in dataloader.cpp in QGit 1.5.6 and other\nversions up to 2pre1 allows local users to overwrite arbitrary files and\nexecute arbitrary code via a symlink attack on temporary files with\npredictable filenames.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4631"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"qgit","source":"https://ubuntu.com/security/cve?package=qgit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qgit","debian":"https://tracker.debian.org/pkg/qgit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.5.5-1.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.5.5-1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4629","published":"2007-08-31T01:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the processLine function in maptemplate.c in MapServer\nbefore 4.10.3 allows attackers to cause a denial of service and possibly\nexecute arbitrary code via a mapfile with a long layer name, group name, or\nmetadata entry name.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4629"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mapserver","source":"https://ubuntu.com/security/cve?package=mapserver","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mapserver","debian":"https://tracker.debian.org/pkg/mapserver","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"4.10.3-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"4.10.3-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"4.10.3-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"4.10.3-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"4.10.3-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":76200,"limit":20,"total_results":79316}