CVE-2007-4661

Publication date 4 September 2007

Last updated 24 July 2024


Ubuntu priority

The chunk_split function in string.c in PHP 5.2.3 does not properly calculate the needed buffer size due to precision loss when performing integer arithmetic with floating point numbers, which has unknown attack vectors and impact, possibly resulting in a heap-based buffer overflow. NOTE: this is due to an incomplete fix for CVE-2007-2872.

Status

Package Ubuntu Release Status
php5 7.10 gutsy
Fixed 5.2.3-1ubuntu6.1
7.04 feisty
Fixed 5.2.1-0ubuntu1.5
6.10 edgy
Fixed 5.1.6-1ubuntu2.7
6.06 LTS dapper
Fixed 5.1.2-1ubuntu3.10

References

Related Ubuntu Security Notices (USN)

    • USN-549-1
    • PHP vulnerabilities
    • 29 November 2007

Other references