Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to obtain sensitive information (memory contents) or cause a denial of service (thread crash) via a large len value to the (1) strspn or (2) strcspn function, which triggers an out-of-bounds read. NOTE: this affects different product versions than CVE-2007-3996.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHP 'strspn或strcspn'整数溢出漏洞
Vulnerability Description
PHP是广泛使用的通用目的脚本语言,特别适合于Web开发,可嵌入到HTML中。 PHP存在整数溢出漏洞,允许远程攻击者通过向strspn或strcspn函数传送很大的长度值触发越界读取,导致泄露敏感信息或拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A