PHP < 4.4.7 / 5.2.2 Multiple Vulnerabilities

High Nessus Plugin ID 25159

Synopsis

The remote web server uses a version of PHP that is affected by multiple flaws.

Description

According to its banner, the version of PHP installed on the remote host is older than 4.4.7 / 5.2.2. Such versions may be affected by several issues, including buffer overflows in the GD library.

Solution

Upgrade to PHP 4.4.7 / 5.2.2 or later.

See Also

http://www.php.net/releases/4_4_7.php

http://www.php.net/releases/5_2_2.php

Plugin Details

Severity: High

ID: 25159

File Name: php_4_4_7_or_5_2_2.nasl

Version: 1.37

Type: remote

Family: CGI abuses

Published: 2007/05/04

Updated: 2018/07/24

Dependencies: 48243

Configuration: Enable paranoid mode

Risk Information

Risk Factor: High

CVSS v2.0

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:POC/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:php:php

Required KB Items: www/PHP, Settings/ParanoidReport

Exploit Available: false

Exploit Ease: No exploit is required

Vulnerability Publication Date: 2007/01/29

Reference Information

CVE: CVE-2007-0455, CVE-2007-0911, CVE-2007-1001, CVE-2007-1521, CVE-2007-1285, CVE-2007-1375, CVE-2007-1396, CVE-2007-1399, CVE-2007-1460, CVE-2007-1461, CVE-2007-1484, CVE-2007-1522, CVE-2007-1582, CVE-2007-1583, CVE-2007-1709, CVE-2007-1710, CVE-2007-1717, CVE-2007-1718, CVE-2007-1864, CVE-2007-1883, CVE-2007-2509, CVE-2007-2510, CVE-2007-2511, CVE-2007-2727, CVE-2007-2748, CVE-2007-3998, CVE-2007-4670

BID: 22289, 22764, 22990, 23357, 23813, 23818, 23984, 24012

CWE: 20, 119