CVE-2007-1581

Publication date 21 March 2007

Last updated 24 July 2024


Ubuntu priority

Description

The resource system in PHP 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting the hash_update_file function via a userspace (1) error or (2) stream handler, which can then be used to destroy and modify internal resources. NOTE: it was later reported that PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 are also affected.

Read the notes from the security team

Status

Package Ubuntu Release Status
php5 10.04 LTS lucid Ignored
9.10 karmic Ignored
9.04 jaunty Ignored
8.10 intrepid Ignored end of life, was needed
8.04 LTS hardy Ignored
6.06 LTS dapper Ignored

Notes


mdeslaur

This is MOPS-2010-001 malicious script only, ignoring.