PHP < 4.4.7 / 5.2.2 Multiple Vulnerabilities

High Log Correlation Engine Plugin ID 801085

Synopsis

The remote host is vulnerable to multiple attack vectors.

Description

The remote host is running a version of PHP lower than 4.4.7 or 5.2.2. This version is vulnerable to a number of remote issues. At least one of these issues is related to a buffer overflow attack. An attacker exploiting these flaws would be able to impact confidentiality, integrity, and availability.

Solution

Upgrade to version 4.4.7, 5.2.2 or higher.

See Also

http://.php.net/releases/4_4_7.php

http://.php.net/releases/5_2_2.php

http://.php.net

Plugin Details

Severity: High

ID: 801085

File Name: 801085.prm

Family: Web Servers

Nessus ID: 25159

Risk Information

Risk Factor: High

CVSSv2

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Reference Information

CVE: CVE-2007-1864, CVE-2007-2510, CVE-2007-2727, CVE-2007-2748, CVE-2007-1375, CVE-2007-2509, CVE-2007-1484, CVE-2007-0455, CVE-2007-1001

BID: 22851, 24034, 24012, 22990, 22289, 23357, 23813, 23818, 23984