CVE-2007-4255

Publication date 8 August 2007

Last updated 24 July 2024


Ubuntu priority

Description

Buffer overflow in the mSQL extension in PHP 5.2.3 allows context-dependent attackers to execute arbitrary code via a long first argument to the msql_connect function.

Read the notes from the security team

Status

Package Ubuntu Release Status
php5 7.10 gutsy
Not affected
7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Not affected

Notes


jdstrand

needs malicious script to be effective


kees

mSQL connector is not built in Debian/Ubuntu