CVE-2007-1649
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/03/2007
Last modified:
09/04/2025
Description
PHP 5.2.1 allows context-dependent attackers to read portions of heap memory by executing certain scripts with a serialized data input string beginning with S:, which does not properly track the number of input bytes being processed.
Impact
Base Score 2.0
7.80
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:php:php:5.2.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://secunia.com/advisories/24630
- http://us2.php.net/releases/5_2_2.php
- http://www.mandriva.com/security/advisories?name=MDVSA-2008%3A126
- http://www.php-security.org/MOPB/MOPB-29-2007.html
- http://www.securityfocus.com/bid/23105
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33170
- http://secunia.com/advisories/24630
- http://us2.php.net/releases/5_2_2.php
- http://www.mandriva.com/security/advisories?name=MDVSA-2008%3A126
- http://www.php-security.org/MOPB/MOPB-29-2007.html
- http://www.securityfocus.com/bid/23105
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33170



