Several remote vulnerabilities have been discovered in PHP, a
server-side, HTML-embedded scripting language. The Common
Vulnerabilities and Exposures project identifies the following
problems:
CVE-2007-3799
It was discovered that the session_start() function allowed the
insertion of attributes into the session cookie.
CVE-2007-3998
Mattias Bengtsson and Philip Olausson discovered that a
programming error in the implementation of the wordwrap() function
allowed denial of service through an infinite loop.
CVE-2007-4658
Stanislav Malyshev discovered that a format string vulnerability
in the money_format() function could allow the execution of
arbitrary code.
CVE-2007-4659
Stefan Esser discovered that execution control flow inside the
zend_alter_ini_entry() function in handled incorrectly in case
of a memory limit violation.
CVE-2007-4660
Gerhard Wagner discovered an integer overflow inside the
chunk_split function().
CVE-...
Get the latest Linux and open source security news straight to your inbox.