CVE-2007-1649
Publication date 24 March 2007
Last updated 17 July 2025
Ubuntu priority
Description
PHP 5.2.1 allows context-dependent attackers to read portions of heap memory by executing certain scripts with a serialized data input string beginning with S:, which does not properly track the number of input bytes being processed.