Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2007-6039
Description:PHP 5.2.5 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in (1) the domain parameter to the dgettext function, the message parameter to the (2) dcgettext or (3) gettext function, the msgid1 parameter to the (4) dngettext or (5) ngettext function, or (6) the classname parameter to the stream_wrapper_register function. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless this issue can be demonstrated for code execution.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2007-6039
BugTraq ID: 26426
http://www.securityfocus.com/bid/26426
BugTraq ID: 26428
http://www.securityfocus.com/bid/26428
Bugtraq: 20071113 PHP <= 5.2.5 Gettext Lib Multiple Denial of service (Google Search)
http://www.securityfocus.com/archive/1/483648/100/0/threaded
Bugtraq: 20071113 PHP <= 5.2.5 stream_wrapper_register() denial of service (Google Search)
http://www.securityfocus.com/archive/1/483644/100/0/threaded
http://securityreason.com/securityalert/3365
http://securityreason.com/securityalert/3366
XForce ISS Database: php-multiple-gettext-dos(38443)
https://exchange.xforce.ibmcloud.com/vulnerabilities/38443
XForce ISS Database: php-streamwrapperregister-dos(38442)
https://exchange.xforce.ibmcloud.com/vulnerabilities/38442




© 1998-2025 E-Soft Inc. All rights reserved.