CVE-2007-1889

Publication date 6 April 2007

Last updated 17 July 2025


Ubuntu priority

Description

Integer signedness error in the _zend_mm_alloc_int function in the Zend Memory Manager in PHP 5.2.0 allows remote attackers to execute arbitrary code via a large emalloc request, related to an incorrect signed long cast, as demonstrated via the HTTP SOAP client in PHP, and via a call to msg_receive with the largest positive integer value of maxsize.

Status

Package Ubuntu Release Status
php5 7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Not affected


Access our resources on patching vulnerabilities