CVE-2006-4482

PHP < 5.1.5 - Heap-Based Buffer Overflow in str_repeat and wordwrap Functions

Title source: llm
STIX 2.1

Description

Multiple heap-based buffer overflows in the (1) str_repeat and (2) wordwrap functions in ext/standard/string.c in PHP before 5.1.5, when used on a 64-bit system, have unspecified impact and attack vectors, a different vulnerability than CVE-2006-1990.

References (30)

Core 30
Core References
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016984
Patch, Release Notes, Vendor Advisory x_refsource_confirm
http://www.php.net/release_5_1_5.php
Broken Link x_refsource_confirm
https://issues.rpath.com/browse/RPL-683
Not Applicable, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21768
Third Party Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2006-0669.html
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22487
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-342-1
Third Party Advisory x_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2006-221.htm
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22039
Broken Link vendor-advisory x_refsource_turbo
http://www.turbolinux.com/security/2006/TLSA-2006-38.txt
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2006-0688.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2006/dsa-1206
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/19582
Not Applicable, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22004
Third Party Advisory x_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2006-222.htm
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22538
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22713
Third Party Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2006-0682.html
Not Applicable, Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21546
Not Applicable, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22440
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/447866/100/0/threaded
Not Applicable, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22069
Permissions Required vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3318
Not Applicable, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22225
Third Party Advisory x_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2006-223.htm
Release Notes, Vendor Advisory x_refsource_confirm
http://www.php.net/ChangeLog-5.php#5.1.5
Broken Link vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2006_52_php.html

Scores

EPSS 0.0410
EPSS Percentile 88.7%

Details

CWE
CWE-787
Status published
Products (5)
canonical/ubuntu_linux 5.04
canonical/ubuntu_linux 5.10
canonical/ubuntu_linux 6.06
debian/debian_linux 3.1
php/php < 5.1.5
Published Aug 31, 2006
Tracked Since Feb 18, 2026