Record summary

CVE-2003-0166 has a selected CVSS score of 7.5; EIP currently links 3 catalogued exploits.

Description

Integer signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via negative arguments to functions such as (1) socket_recv, (2) socket_recvfrom, and possibly other functions.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
3

Proofs of concept

3

Catalogued exploits

ExploitDBPHP 4.3 - 'socket_iovec_alloc()' Integer OverflowExploitDB exploitby Sir MordredNot analyzed1 file
ExploitDB

PoC details
ExploitDBPHP 4.x - 'socket_recv()' Signed Integer Memory CorruptionExploitDB exploitby Sir MordredNot analyzed1 file
ExploitDB

PoC details
ExploitDBPHP 4.x - 'socket_recvfrom()' Signed Integer Memory CorruptionExploitDB exploitby Sir MordredNot analyzed1 file
ExploitDB

PoC details

References

7