It was discovered that the session_start() function allowed the
insertion of attributes into the session cookie.
CVE-2007-3998
Mattias Bengtsson and Philip Olausson discovered that a
programming error in the implementation of the wordwrap() function
allowed denial of service through an infinite loop.
CVE-2007-4658
Stanislav Malyshev discovered that a format string vulnerability
in the money_format() function could allow the execution of
arbitrary code.
CVE-2007-4659
Stefan Esser discovered that execution control flow inside the
zend_alter_ini_entry() function in handled incorrectly in case
of a memory limit violation.
CVE-2007-4660
Gerhard Wagner discovered an integer overflow inside the
chunk_split function().
CVE-2007-5898
Rasmus Lerdorf discovered that incorrect parsing of multibyte
sequences may lead to disclosure of memory contents.
CVE-2007-5899
It was discovered that the output_add_rewrite_var() func...
Get the latest Linux and open source security news straight to your inbox.