Security Advisory

CVE-2007-1376

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2007-03-10 00:00:00
Last updated 2024-08-07 12:50:35
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspond to a shmop resource, which allows context-dependent attackers to read and write arbitrary memory locations via arguments associated with an inappropriate resource, as demonstrated by a GD Image resource.