CVE-2007-2510 Information

Share on:

Description

Buffer overflow in the make_http_soap_request function in PHP before 5.2.2 has unknown impact and remote attack vectors possibly related to \/\ (slash) characters.

Reference

http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html http://osvdb.org/34675 http://secunia.com/advisories/25187 http://secunia.com/advisories/25191 http://secunia.com/advisories/25255 http://secunia.com/advisories/25318 http://secunia.com/advisories/25372 http://secunia.com/advisories/25445 http://secunia.com/advisories/26048 http://security.gentoo.org/glsa/glsa-200705-19.xml http://us2.php.net/releases/5_2_2.php http://viewcvs.php.net/viewvc.cgi/php-src/ext/soap/php_http.c?r1=1.77.2.11.2.5&r2=1.77.2.11.2.6 http://www.debian.org/security/2007/dsa-1295 http://www.mandriva.com/security/advisories?name=MDKSA-2007:102 http://www.redhat.com/support/errata/RHSA-2007-0355.html http://www.securityfocus.com/bid/23813 http://www.securityfocus.com/bid/24034 http://www.securitytracker.com/id?1018023 http://www.trustix.org/errata/2007/0017/ http://www.ubuntu.com/usn/usn-462-1 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A10715 https://rhn.redhat.com/errata/RHSA-2007-0348.html