{"cves":[{"id":"CVE-2007-1375","published":"2007-03-10T00:19:00","updated_at":"2025-07-17T16:40:55.017532+00:00","description":"\nInteger overflow in the substr_compare function in PHP 5.2.1 and earlier\nallows context-dependent attackers to read sensitive memory via a large\nvalue in the length argument, a different vulnerability than CVE-2006-1991.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-455-1","https://www.cve.org/CVERecord?id=CVE-2007-1375"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.6-1ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-455-1"],"notices":[{"id":"USN-455-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-04-27T21:10:26","description":"Stefan Esser discovered multiple vulnerabilities in the \"Month of PHP\nbugs\".\n\nThe substr_compare() function did not sufficiently verify its length\nargument. This might be exploited to read otherwise unaccessible\nmemory, which might lead to information disclosure. (CVE-2007-1375)\n\nThe shared memory (shmop) functions did not verify resource types,\nthus they could be called with a wrong resource type that might\ncontain user supplied data. This could be exploited to read and write\narbitrary memory addresses of the PHP interpreter. This issue does\nnot affect Ubuntu 7.04. (CVE-2007-1376)\n\nThe php_binary handler of the session extension was missing a boundary\ncheck. When unserializing overly long variable names this could be\nexploited to read up to 126 bytes of memory, which might lead to\ninformation disclosure. (CVE-2007-1380)\n\nThe internal array_user_key_compare() function, as used for example by\nthe PHP function uksort(), incorrectly handled memory unreferencing of\nits arguments. This could have been exploited to execute arbitrary\ncode with the privileges of the PHP interpreter, and thus\ncircumventing any disable_functions, open_basedir, or safe_mode\nrestrictions. (CVE-2007-1484)\n\nThe session_regenerate_id() function did not properly clean up the\nformer session identifier variable. This could be exploited to crash\nthe PHP interpreter, possibly also remotely. (CVE-2007-1521)\n\nUnder certain conditions the mb_parse_str() could cause the\nregister_globals configuration option to become permanently enabled.\nThis opened an attack vector for a large and common class of\nvulnerabilities. (CVE-2007-1583)\n\nThe session extension did not set the correct reference count value\nfor the session variables. By unsetting _SESSION and HTTP_SESSION_VARS\n(or tricking a PHP script into doing that) this could be exploited to\nexecute arbitrary code with the privileges of the PHP interpreter. This\nissue does not affect Ubuntu 7.04. (CVE-2007-1700)\n\nThe mail() function did not correctly escape control characters in\nmultiline email headers. This could be remotely exploited to inject\narbitrary email headers. (CVE-2007-1718)\n\nThe php_stream_filter_create() function had an off-by-one buffer\noverflow in the handling of wildcards. This could be exploited to\nremotely crash the PHP interpreter. This issue does not affect Ubuntu\n7.04. (CVE-2007-1824)\n\nWhen calling the sqlite_udf_decode_binary() with special arguments, a\nbuffer overflow happened. Depending on the application this could be\nlocally or remotely exploited to execute arbitrary code with the\nprivileges of the PHP interpreter. (CVE-2007-1887 CVE-2007-1888)\n\nThe FILTER_VALIDATE_EMAIL filter extension used a wrong\nregular expression that allowed injecting a newline character at the\nend of the email string. This could be exploited to inject \narbitrary email headers. This issue only affects Ubuntu 7.04.\n(CVE-2007-1900)","is_hidden":false,"release_packages":{"dapper":[{"name":"php5-cli","version":"5.1.2-1ubuntu3.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.7","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-sqlite","version":"5.1.2-1ubuntu3.7","is_source":false,"source_link":"","version_link":""}],"feisty":[{"name":"php5-cli","version":"5.2.1-0ubuntu1.1","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.2.1-0ubuntu1.1","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.2.1-0ubuntu1.1","is_source":false,"source_link":"","version_link":""},{"name":"php5-sqlite","version":"5.2.1-0ubuntu1.1","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"php5-cli","version":"5.1.6-1ubuntu2.4","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.6-1ubuntu2.4","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.6-1ubuntu2.4","is_source":false,"source_link":"","version_link":""},{"name":"php5-sqlite","version":"5.1.6-1ubuntu2.4","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1888","CVE-2007-1700","CVE-2007-1380","CVE-2007-1900","CVE-2007-1375","CVE-2007-1887","CVE-2007-1521","CVE-2007-1718","CVE-2007-1484","CVE-2007-1376","CVE-2007-1824","CVE-2007-1583"]}]},{"id":"CVE-2007-1371","published":"2007-03-10T00:19:00","updated_at":"2025-07-17T16:40:55.017532+00:00","description":"\nMultiple buffer overflows in Conquest 8.2a and earlier (1) allow local\nusers to gain privileges by querying a metaserver that sends a long server\nentry processed by metaGetServerList and allow remote metaservers to\nexecute arbitrary code via a long server entry processed by\nmetaGetServerList; (2) allow attackers to have an unknown impact by\nexceeding the configured number of metaservers; and allow remote attackers\nto corrupt memory via a SP_CLIENTSTAT packet with certain values of (3)\nunum or (4) snum, different vulnerabilities than CVE-2003-0933.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1371"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"conquest","source":"https://ubuntu.com/security/cve?package=conquest","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=conquest","debian":"https://tracker.debian.org/pkg/conquest","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"8.2b-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"8.2b-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"8.2b-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"8.2b-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"8.2b-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.2b","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0005","published":"2007-03-10T00:19:00","updated_at":"2025-07-17T16:40:24.719687+00:00","description":"\nMultiple buffer overflows in the (1) read and (2) write handlers in the\nOmnikey CardMan 4040 driver in the Linux kernel before 2.6.21-rc3 allow\nlocal users to gain privileges.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-489-1","https://ubuntu.com/security/notices/USN-486-1","https://www.cve.org/CVERecord?id=CVE-2007-0005"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-29.58","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.17","debian":"https://tracker.debian.org/pkg/linux-source-2.6.17","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.17.1-12.40","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.20-16.31","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-489-1","USN-486-1"],"notices":[{"id":"USN-489-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.","references":[],"published":"2007-07-19T13:57:31","description":"A flaw was discovered in dvb ULE decapsulation. A remote attacker could\nsend a specially crafted message and cause a denial of service.\n(CVE-2006-4623)\n\nThe compat_sys_mount function allowed local users to cause a denial of\nservice when mounting a smbfs filesystem in compatibility mode.\n(CVE-2006-7203)\n\nThe Omnikey CardMan 4040 driver (cm4040_cs) did not limit the size of\nbuffers passed to read() and write(). A local attacker could exploit\nthis to execute arbitrary code with kernel privileges. (CVE-2007-0005)\n\nDue to an variable handling flaw in the ipv6_getsockopt_sticky()\nfunction a local attacker could exploit the getsockopt() calls to read\narbitrary kernel memory. This could disclose sensitive data.\n(CVE-2007-1000)\n\nIlja van Sprundel discovered that Bluetooth setsockopt calls could\nleak kernel memory contents via an uninitialized stack buffer. A local\nattacker could exploit this flaw to view sensitive kernel information.\n(CVE-2007-1353)\n\nA flaw was discovered in the handling of netlink messages. Local\nattackers could cause infinite recursion leading to a denial of service.\n(CVE-2007-1861)\n\nThe random number generator was hashing a subset of the available entropy,\nleading to slightly less random numbers. Additionally, systems without\nan entropy source would be seeded with the same inputs at boot time,\nleading to a repeatable series of random numbers. (CVE-2007-2453)\n\nA flaw was discovered in the PPP over Ethernet implementation. Local\nattackers could manipulate ioctls and cause kernel memory consumption\nleading to a denial of service. (CVE-2007-2525)\n\nAn integer underflow was discovered in the cpuset filesystem. If mounted,\nlocal attackers could obtain kernel memory using large file offsets\nwhile reading the tasks file. This could disclose sensitive data.\n(CVE-2007-2875)\n\nVilmos Nebehaj discovered that the SCTP netfilter code did not correctly\nvalidate certain states. A remote attacker could send a specially\ncrafted packet causing a denial of service. (CVE-2007-2876)\n\nLuca Tettamanti discovered a flaw in the VFAT compat ioctls on 64-bit\nsystems. A local attacker could corrupt a kernel_dirent struct and\ncause a denial of service. (CVE-2007-2878)\n\nA flaw was discovered in the cluster manager. A remote attacker could\nconnect to the DLM port and block further DLM operations.\n(CVE-2007-3380)\n\nA flaw was discovered in the usblcd driver. A local attacker could\ncause large amounts of kernel memory consumption, leading to a denial\nof service. (CVE-2007-3513)","is_hidden":false,"release_packages":{"dapper":[{"name":"linux-image-2.6.15-28-amd64-generic","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-powerpc-smp","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-amd64-k8","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-686","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-powerpc64-smp","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-server-bigiron","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-sparc64-smp","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-mckinley","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-server","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-k7","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-mckinley-smp","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-amd64-server","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-amd64-xeon","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-386","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-powerpc","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-sparc64","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-4623","CVE-2006-7203","CVE-2007-0005","CVE-2007-1000","CVE-2007-1353","CVE-2007-1861","CVE-2007-2453","CVE-2007-2525","CVE-2007-2875","CVE-2007-2876","CVE-2007-2878","CVE-2007-3380","CVE-2007-3513"]},{"id":"USN-486-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the Ubuntu 6.10 kernel updates\nhave been given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If you\nuse linux-restricted-modules, you have to update that package as well to\nget modules which work with the new kernel version. Unless you manually\nuninstalled the standard kernel metapackages (linux-386, linux-powerpc,\nlinux-amd64-generic, etc), a standard system upgrade will automatically\nperform this as well.","references":[],"published":"2007-07-18T22:57:48","description":"The compat_sys_mount function allowed local users to cause a denial of\nservice when mounting a smbfs filesystem in compatibility mode.\n(CVE-2006-7203)\n\nThe Omnikey CardMan 4040 driver (cm4040_cs) did not limit the size of\nbuffers passed to read() and write(). A local attacker could exploit\nthis to execute arbitrary code with kernel privileges. (CVE-2007-0005)\n\nDue to a variable handling flaw in the ipv6_getsockopt_sticky()\nfunction a local attacker could exploit the getsockopt() calls to\nread arbitrary kernel memory. This could disclose sensitive data.\n(CVE-2007-1000)\n\nIlja van Sprundel discovered that Bluetooth setsockopt calls could leak\nkernel memory contents via an uninitialized stack buffer. A local \nattacker could exploit this flaw to view sensitive kernel information.\n(CVE-2007-1353)\n\nA flaw was discovered in the handling of netlink messages. Local\nattackers could cause infinite recursion leading to a denial of service.\n(CVE-2007-1861)\n\nA flaw was discovered in the IPv6 stack's handling of type 0 route\nheaders. By sending a specially crafted IPv6 packet, a remote attacker\ncould cause a denial of service between two IPv6 hosts. (CVE-2007-2242)\n\nThe random number generator was hashing a subset of the available\nentropy, leading to slightly less random numbers. Additionally, systems\nwithout an entropy source would be seeded with the same inputs at boot\ntime, leading to a repeatable series of random numbers. (CVE-2007-2453)\n\nA flaw was discovered in the PPP over Ethernet implementation. Local\nattackers could manipulate ioctls and cause kernel memory consumption\nleading to a denial of service. (CVE-2007-2525)\n\nAn integer underflow was discovered in the cpuset filesystem. If mounted,\nlocal attackers could obtain kernel memory using large file offsets\nwhile reading the tasks file. This could disclose sensitive data.\n(CVE-2007-2875)\n\nVilmos Nebehaj discovered that the SCTP netfilter code did not correctly\nvalidate certain states. A remote attacker could send a specially\ncrafted packet causing a denial of service. (CVE-2007-2876)\n\nLuca Tettamanti discovered a flaw in the VFAT compat ioctls on 64-bit\nsystems. A local attacker could corrupt a kernel_dirent struct and\ncause a denial of service. (CVE-2007-2878)","is_hidden":false,"release_packages":{"edgy":[{"name":"linux-image-2.6.17-12-mckinley","version":"2.6.17.1-12.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-12-powerpc64-smp","version":"2.6.17.1-12.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-12-hppa32","version":"2.6.17.1-12.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-12-hppa64","version":"2.6.17.1-12.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-12-sparc64-smp","version":"2.6.17.1-12.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-12-generic","version":"2.6.17.1-12.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-12-powerpc-smp","version":"2.6.17.1-12.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-12-386","version":"2.6.17.1-12.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-12-server-bigiron","version":"2.6.17.1-12.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-12-itanium","version":"2.6.17.1-12.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-12-powerpc","version":"2.6.17.1-12.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-12-sparc64","version":"2.6.17.1-12.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-12-server","version":"2.6.17.1-12.39","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-2242","CVE-2006-7203","CVE-2007-0005","CVE-2007-1000","CVE-2007-1353","CVE-2007-1861","CVE-2007-2453","CVE-2007-2525","CVE-2007-2875","CVE-2007-2876","CVE-2007-2878"]}]},{"id":"CVE-2007-1359","published":"2007-03-08T22:19:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInterpretation conflict in ModSecurity (mod_security) 2.1.0 and earlier\nallows remote attackers to bypass request rules via\napplication/x-www-form-urlencoded POST data that contains an ASCIIZ (0x00)\nbyte, which mod_security treats as a terminator even though it is still\nprocessed as normal data by some HTTP parsers including PHP 5.2.0, and\npossibly parsers in Perl, and Python.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"PoC: http://www.php-security.org/MOPB/BONUS-12-2007.html"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.php-security.org/MOPB/BONUS-12-2007.html","https://www.cve.org/CVERecord?id=CVE-2007-1359"],"bugs":[""],"patches":{"libapache-mod-security":["upstream: http://mod-security.svn.sourceforge.net/viewvc/mod-security?view=rev&revision=80","upstream: http://mod-security.svn.sourceforge.net/viewvc/mod-security?view=rev&revision=104"]},"tags":{},"packages":[{"name":"libapache-mod-security","source":"https://ubuntu.com/security/cve?package=libapache-mod-security","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libapache-mod-security","debian":"https://tracker.debian.org/pkg/libapache-mod-security","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.1.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1343","published":"2007-03-08T22:19:00","updated_at":"2025-07-17T16:40:52.862747+00:00","description":"\nincludes/functions.php in Craig Knudsen WebCalendar before 1.0.5 does not\nprotect the noSet variable from external modification, which allows remote\nattackers to set arbitrary global variables via a URL with modified values\nin the noSet parameter, which leads to resultant vulnerabilities that\nprobably include remote file inclusion and other issues.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1343"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"webcalendar","source":"https://ubuntu.com/security/cve?package=webcalendar","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webcalendar","debian":"https://tracker.debian.org/pkg/webcalendar","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.0.5-12","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.0.5-12","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.0.5-12","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.0.5-12","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.0.5-12","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1329","published":"2007-03-07T21:19:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDirectory traversal vulnerability in SQL-Ledger, and LedgerSMB before\n1.1.5, allows remote attackers to read and overwrite arbitrary files, and\nexecute arbitrary code, via . (dot) characters adjacent to (1) users and\n(2) users/members strings, which are removed by blacklisting functions that\nfilter these strings and collapse into .. (dot dot) sequences.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"According to Debian:\n\"It's documented behaviour that SQL-Ledger should only be run\nin an authenticated HTTP zone and without untrusted users\"\nSetting esm-apps/xenial to ignored"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1329"],"bugs":[""],"patches":{"sql-ledger":[]},"tags":{},"packages":[{"name":"sql-ledger","source":"https://ubuntu.com/security/cve?package=sql-ledger","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sql-ledger","debian":"https://tracker.debian.org/pkg/sql-ledger","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1326","published":"2007-03-07T21:19:00","updated_at":"2025-07-17T16:40:52.862747+00:00","description":"\nSQL injection vulnerability in index.php in Serendipity 1.1.1 allows remote\nattackers to execute arbitrary SQL commands via the serendipity[multiCat][]\nparameter.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1326"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"serendipity","source":"https://ubuntu.com/security/cve?package=serendipity","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=serendipity","debian":"https://tracker.debian.org/pkg/serendipity","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.1.4-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.1.4-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1325","published":"2007-03-07T21:19:00","updated_at":"2025-07-17T16:40:52.862747+00:00","description":"\nThe PMA_ArrayWalkRecursive function in libraries/common.lib.php in\nphpMyAdmin before 2.10.0.2 does not limit recursion on arrays provided by\nusers, which allows context-dependent attackers to cause a denial of\nservice (web server crash) via an array with many dimensions. NOTE: it\ncould be argued that this vulnerability is caused by a problem in PHP\n(CVE-2006-1549) and the proper fix should be in PHP; if so, then this\nshould not be treated as a vulnerability in phpMyAdmin.","ubuntu_description":"","notes":[{"author":"wgrant","note":"PMASA-2007-3"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1325"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"phpmyadmin","source":"https://ubuntu.com/security/cve?package=phpmyadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpmyadmin","debian":"https://tracker.debian.org/pkg/phpmyadmin","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.9.1.1-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.10.0.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-7162","published":"2007-03-07T21:19:00","updated_at":"2025-07-17T16:40:21.076075+00:00","description":"\nPuTTY 0.59 and earlier uses weak file permissions for (1) ppk files\ncontaining private keys generated by puttygen and (2) session logs created\nby putty, which allows local users to gain sensitive information by reading\nthese files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-7162"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"putty","source":"https://ubuntu.com/security/cve?package=putty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=putty","debian":"https://tracker.debian.org/pkg/putty","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-7151","published":"2007-03-07T20:19:00","updated_at":"2025-07-17T16:40:21.076075+00:00","description":"\nUntrusted search path vulnerability in the libtool-ltdl library\n(libltdl.so) 1.5.22-2.3 in Fedora Core 5 might allow local users to execute\narbitrary code via a malicious library in the (1) hwcap, (2) 0, and (3)\nnosegneg subdirectories.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-7151"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"libtool","source":"https://ubuntu.com/security/cve?package=libtool","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libtool","debian":"https://tracker.debian.org/pkg/libtool","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-7139","published":"2007-03-07T20:19:00","updated_at":"2025-07-17T16:40:21.076075+00:00","description":"\nKmail 1.9.1 on KDE 3.5.2, with \"Prefer HTML to Plain Text\" enabled, allows\nremote attackers to cause a denial of service (crash) via an HTML e-mail\nwith certain table and frameset tags that trigger a segmentation fault,\npossibly involving invalid free or delete operations.","ubuntu_description":"","notes":[{"author":"kees","note":"not a security issue."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-7139"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"kdepim","source":"https://ubuntu.com/security/cve?package=kdepim","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kdepim","debian":"https://tracker.debian.org/pkg/kdepim","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1308","published":"2007-03-07T00:19:00","updated_at":"2025-07-17T16:40:52.862747+00:00","description":"\necma/kjs_html.cpp in KDE JavaScript (KJS), as used in Konqueror in KDE\n3.5.5, allows remote attackers to cause a denial of service (crash) by\naccessing the content of an iframe with an ftp:// URI in the src attribute,\nprobably due to a NULL pointer dereference.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-447-1","https://www.cve.org/CVERecord?id=CVE-2007-1308"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"kdelibs","source":"https://ubuntu.com/security/cve?package=kdelibs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kdelibs","debian":"https://tracker.debian.org/pkg/kdelibs","statuses":[{"release_codename":"dapper","status":"released","description":"3.5.2-0ubuntu18.5","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.5.5-0ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.5.6-0ubuntu14.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-447-1"],"notices":[{"id":"USN-447-1","title":"KDE library vulnerabilities","summary":"KDE library vulnerabilities","instructions":"After a standard system upgrade you need to restart your session or \nreboot your computer to effect the necessary changes.","references":[],"published":"2007-03-29T03:12:12","description":"It was discovered that Konqueror did not correctly handle iframes from \nJavaScript. If a user were tricked into visiting a malicious website, \nKonqueror could crash, resulting in a denial of service. (CVE-2007-1308)\n\nA flaw was discovered in how Konqueror handled PASV FTP responses. If a \nuser were tricked into visiting a malicious FTP server, a remote \nattacker could perform a port-scan of machines within the user's \nnetwork, leading to private information disclosure. (CVE-2007-1564)","is_hidden":false,"release_packages":{"dapper":[{"name":"kdelibs4c2a","version":"4:3.5.2-0ubuntu18.3","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"kdelibs4c2","version":"4:3.4.3-0ubuntu2.3","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"kdelibs4c2a","version":"4:3.5.5-0ubuntu3.1.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1564","CVE-2007-1308"]}]},{"id":"CVE-2007-1306","published":"2007-03-07T00:19:00","updated_at":"2025-07-17T16:40:52.862747+00:00","description":"\nAsterisk 1.4 before 1.4.1 and 1.2 before 1.2.16 allows remote attackers to\ncause a denial of service (crash) by sending a Session Initiation Protocol\n(SIP) packet without a URI and SIP-version header, which results in a NULL\npointer dereference.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1306"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"asterisk","source":"https://ubuntu.com/security/cve?package=asterisk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=asterisk","debian":"https://tracker.debian.org/pkg/asterisk","statuses":[{"release_codename":"dapper","status":"released","description":"1.2.7.1.dfsg-2ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.2.12.1.dfsg-1ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.2.16~dfsg-1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.2.16~dfsg-1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.16","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1287","published":"2007-03-06T20:19:00","updated_at":"2025-07-17T16:40:52.862747+00:00","description":"\nA regression error in the phpinfo function in PHP 4.4.3 to 4.4.6, and PHP\n6.0 in CVS, allows remote attackers to conduct cross-site scripting (XSS)\nattacks via GET, POST, or COOKIE array values, which are not escaped in the\nphpinfo output, as originally fixed for CVE-2005-3388.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1287"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php4","source":"https://ubuntu.com/security/cve?package=php4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php4","debian":"https://tracker.debian.org/pkg/php4","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1286","published":"2007-03-06T20:19:00","updated_at":"2025-07-17T16:40:52.862747+00:00","description":"\nInteger overflow in PHP 4.4.4 and earlier allows remote context-dependent\nattackers to execute arbitrary code via a long string to the unserialize\nfunction, which triggers the overflow in the ZVAL reference counter.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1286"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php4","source":"https://ubuntu.com/security/cve?package=php4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php4","debian":"https://tracker.debian.org/pkg/php4","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1285","published":"2007-03-06T20:19:00","updated_at":"2025-07-17T16:40:52.862747+00:00","description":"\nThe Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows\nremote attackers to cause a denial of service (stack exhaustion and PHP\ncrash) via deeply nested arrays, which trigger deep recursion in the\nvariable destruction routines.","ubuntu_description":"","notes":[{"author":"kees","note":"crash only, no code execution. input needs to be validated by application."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-549-1","https://www.cve.org/CVERecord?id=CVE-2007-1285"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-549-1"],"notices":[{"id":"USN-549-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2007-11-29T22:38:09.391050","description":"It was discovered that the wordwrap function did not correctly\ncheck lengths. Remote attackers could exploit this to cause\na crash or monopolize CPU resources, resulting in a denial of\nservice. (CVE-2007-3998)\n\nInteger overflows were discovered in the strspn and strcspn functions.\nAttackers could exploit this to read arbitrary areas of memory, possibly\ngaining access to sensitive information. (CVE-2007-4657)\n\nStanislav Malyshev discovered that money_format function did not correctly\nhandle certain tokens. If a PHP application were tricked into processing\na bad format string, a remote attacker could execute arbitrary code with\napplication privileges. (CVE-2007-4658)\n\nIt was discovered that the php_openssl_make_REQ function did not\ncorrectly check buffer lengths. A remote attacker could send a\nspecially crafted message and execute arbitrary code with application\nprivileges. (CVE-2007-4662)\n\nIt was discovered that certain characters in session cookies were not\nhandled correctly. A remote attacker could injection values which could\nlead to altered application behavior, potentially gaining additional\nprivileges. (CVE-2007-3799)\n\nGerhard Wagner discovered that the chunk_split function did not\ncorrectly handle long strings. A remote attacker could exploit this\nto execute arbitrary code with application privileges. (CVE-2007-2872,\nCVE-2007-4660, CVE-2007-4661)\n\nStefan Esser discovered that deeply nested arrays could be made to\nfill stack space. A remote attacker could exploit this to cause a\ncrash or monopolize CPU resources, resulting in a denial of service.\n(CVE-2007-1285, CVE-2007-4670)\n\nRasmus Lerdorf discovered that the htmlentities and htmlspecialchars\nfunctions did not correctly stop when handling partial multibyte\nsequences. A remote attacker could exploit this to read certain areas of\nmemory, possibly gaining access to sensitive information. (CVE-2007-5898)\n\nIt was discovered that the output_add_rewrite_var fucntion would\nsometimes leak session id information to forms targeting remote URLs.\nMalicious remote sites could use this information to gain access to a\nPHP application user's login credentials. (CVE-2007-5899)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"php5","version":"5.2.3-1ubuntu6.1","description":"","is_source":true},{"name":"php5-cli","version":"5.2.3-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.1"},{"name":"php5-cgi","version":"5.2.3-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.1"},{"name":"libapache2-mod-php5","version":"5.2.3-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.1"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.10","description":"","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.10"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.10"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.10"}],"feisty":[{"name":"php5","version":"5.2.1-0ubuntu1.5","description":"","is_source":true},{"name":"php5-cli","version":"5.2.1-0ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.5"},{"name":"php5-cgi","version":"5.2.1-0ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.5"},{"name":"libapache2-mod-php5","version":"5.2.1-0ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.5"}],"edgy":[{"name":"php5","version":"5.1.6-1ubuntu2.7","description":"","is_source":true},{"name":"php5-cli","version":"5.1.6-1ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.6-1ubuntu2.7"},{"name":"php5-cgi","version":"5.1.6-1ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.6-1ubuntu2.7"},{"name":"libapache2-mod-php5","version":"5.1.6-1ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.6-1ubuntu2.7"}]},"type":"USN","cves_ids":["CVE-2007-1285","CVE-2007-2872","CVE-2007-3799","CVE-2007-3998","CVE-2007-4657","CVE-2007-4658","CVE-2007-4660","CVE-2007-4661","CVE-2007-4662","CVE-2007-4670","CVE-2007-5898","CVE-2007-5899"]}]},{"id":"CVE-2007-1269","published":"2007-03-06T20:19:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGNUMail 1.1.2 and earlier does not properly use the --status-fd argument\nwhen invoking GnuPG, which prevents GNUMail from visually distinguishing\nbetween signed and unsigned portions of OpenPGP messages with multiple\ncomponents, which allows remote attackers to forge the contents of a\nmessage without detection.","ubuntu_description":"","notes":[{"author":"fujitsu","note":"Not important, as GnuPG was fixed in CVE-2007-1263."}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1269"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"gnumail","source":"https://ubuntu.com/security/cve?package=gnumail","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gnumail","debian":"https://tracker.debian.org/pkg/gnumail","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1268","published":"2007-03-06T20:19:00","updated_at":"2025-07-17T16:40:51.108389+00:00","description":"\nMutt 1.5.13 and earlier does not properly use the --status-fd argument when\ninvoking GnuPG, which prevents Mutt from visually distinguishing between\nsigned and unsigned portions of OpenPGP messages with multiple components,\nwhich allows remote attackers to forge the contents of a message without\ndetection.","ubuntu_description":"","notes":[{"author":"kees","note":"feature-request not security issue since gpg is fixed with CVE-2007-1263"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1268"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mutt","source":"https://ubuntu.com/security/cve?package=mutt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mutt","debian":"https://tracker.debian.org/pkg/mutt","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1267","published":"2007-03-06T20:19:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSylpheed 2.2.7 and earlier does not properly use the --status-fd argument\nwhen invoking GnuPG, which prevents Sylpheed from visually distinguishing\nbetween signed and unsigned portions of OpenPGP messages with multiple\ncomponents, which allows remote attackers to forge the contents of a\nmessage without detection.","ubuntu_description":"","notes":[{"author":"fujitsu","note":"Not important, as GnuPG was fixed in CVE-2007-1263."}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1267"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"sylpheed","source":"https://ubuntu.com/security/cve?package=sylpheed","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sylpheed","debian":"https://tracker.debian.org/pkg/sylpheed","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1266","published":"2007-03-06T20:19:00","updated_at":"2025-07-17T16:40:51.108389+00:00","description":"\nEvolution 2.8.1 and earlier does not properly use the --status-fd argument\nwhen invoking GnuPG, which prevents Evolution from visually distinguishing\nbetween signed and unsigned portions of OpenPGP messages with multiple\ncomponents, which allows remote attackers to forge the contents of a\nmessage without detection.","ubuntu_description":"","notes":[{"author":"kees","note":"feature-request not security issue since gpg is fixed with CVE-2007-1263"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1266"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"evolution","source":"https://ubuntu.com/security/cve?package=evolution","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=evolution","debian":"https://tracker.debian.org/pkg/evolution","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":76800,"limit":20,"total_results":79316}