PHP < 4.4.7 / 5.2.2 Multiple Vulnerabilities

high Log Correlation Engine Plugin ID 801085

Synopsis

The remote host is vulnerable to multiple attack vectors.

Description

The remote host is running a version of PHP lower than 4.4.7 or 5.2.2. This version is vulnerable to a number of remote issues. At least one of these issues is related to a buffer overflow attack. An attacker exploiting these flaws would be able to impact confidentiality, integrity, and availability.

Solution

Upgrade to version 4.4.7, 5.2.2 or higher.

See Also

http://.php.net/releases/4_4_7.php

http://.php.net/releases/5_2_2.php

http://.php.net

Plugin Details

Severity: High

ID: 801085

Family: Web Servers

Nessus ID: 25159

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Reference Information

CVE: CVE-2007-0455, CVE-2007-1001, CVE-2007-1375, CVE-2007-1484, CVE-2007-1864, CVE-2007-2509, CVE-2007-2510, CVE-2007-2727, CVE-2007-2748

BID: 23357, 22289, 22990, 23813, 23818, 23984, 24012, 24034, 22851