CVE-2007-1649

Publication date 24 March 2007

Last updated 17 July 2025


Ubuntu priority

Description

PHP 5.2.1 allows context-dependent attackers to read portions of heap memory by executing certain scripts with a serialized data input string beginning with S:, which does not properly track the number of input bytes being processed.

Status

Package Ubuntu Release Status
php5 7.04 feisty
Fixed 5.2.1-0ubuntu1.4
6.10 edgy
Not affected
6.06 LTS dapper
Not affected