PHP < 4.4.7 / 5.2.2 Multiple Vulnerabilities

high Nessus Plugin ID 25159

Synopsis

The remote web server uses a version of PHP that is affected by multiple flaws.

Description

According to its banner, the version of PHP installed on the remote host is older than 4.4.7 / 5.2.2. Such versions may be affected by several issues, including buffer overflows in the GD library.

Solution

Upgrade to PHP 4.4.7 / 5.2.2 or later.

See Also

http://www.php.net/releases/4_4_7.php

http://www.php.net/releases/5_2_2.php

Plugin Details

Severity: High

ID: 25159

File Name: php_4_4_7_or_5_2_2.nasl

Version: 1.40

Type: remote

Family: CGI abuses

Published: 5/4/2007

Updated: 5/28/2024

Configuration: Enable paranoid mode, Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/a:php:php

Required KB Items: www/PHP, Settings/ParanoidReport

Excluded KB Items: Settings/disable_cgi_scanning

Exploit Ease: No exploit is required

Vulnerability Publication Date: 1/29/2007

Reference Information

CVE: CVE-2007-0455, CVE-2007-0911, CVE-2007-1001, CVE-2007-1285, CVE-2007-1375, CVE-2007-1396, CVE-2007-1399, CVE-2007-1460, CVE-2007-1461, CVE-2007-1484, CVE-2007-1521, CVE-2007-1522, CVE-2007-1582, CVE-2007-1583, CVE-2007-1709, CVE-2007-1710, CVE-2007-1717, CVE-2007-1718, CVE-2007-1864, CVE-2007-1883, CVE-2007-2509, CVE-2007-2510, CVE-2007-2511, CVE-2007-2727, CVE-2007-2748, CVE-2007-3998, CVE-2007-4670

BID: 22289, 22764, 22990, 23357, 23813, 23818, 23984, 24012

CWE: 119, 20