CLSA-2003:691Vendor advisory
http://distro.conectiva.com.br/atualizacoes?id=a&anuncio=000691 CVE-2003-0166
PHP 4.3 - 'socket_iovec_alloc()' Integer Overflow
Record summary
CVE-2003-0166 has a selected CVSS score of 7.5; EIP currently links 3 catalogued exploits.
Description
Integer signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via negative arguments to functions such as (1) socket_recv, (2) socket_recvfrom, and possibly other functions.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 3
Proofs of concept
3Catalogued exploits
ExploitDBPHP 4.3 - 'socket_iovec_alloc()' Integer OverflowExploitDB exploitby Sir MordredNot analyzed1 file
ExploitDBPHP 4.x - 'socket_recv()' Signed Integer Memory CorruptionExploitDB exploitby Sir MordredNot analyzed1 file
ExploitDBPHP 4.x - 'socket_recvfrom()' Signed Integer Memory CorruptionExploitDB exploitby Sir MordredNot analyzed1 file
References
720030326 @(#)Mordred Labs advisory - Integer overflow in PHP memory allocatormailing list
http://marc.info/?l=bugtraq&m=104869828526885&w=2 20030327 RE: FUD-ALARM: @(#)Mordred Labs advisory - Integer overflow in PHP memory allocatormailing list
http://marc.info/?l=bugtraq&m=104878100719467&w=2 20030402 Inaccurate Reports Concerning PHP Vulnerabilitiesmailing list
http://marc.info/?l=bugtraq&m=104931415307111&w=2 7197vdb entry
http://www.securityfocus.com/bid/7197 7198vdb entry
http://www.securityfocus.com/bid/7198 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-0166