CVE-2008-2829

EUVD-2008-2822
php_imap.c in PHP 5.2.5, 5.2.6, 4.x, and other versions, uses obsolete API calls that allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long IMAP request, which triggers an "rfc822.c legacy routine buffer overflow" error message, related to the rfc822_write_address function.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
Affected Products (NVD)
VendorProductVersion
phpphp
𝑥
≤ 4.4.9
phpphp
5.2.5
phpphp
5.2.6
canonicalubuntu_linux
6.06
canonicalubuntu_linux
7.04
canonicalubuntu_linux
7.10
canonicalubuntu_linux
8.04
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
php-imap
dapper
ignored
hardy
Fixed 5.2.3-0ubuntu3.1
released
intrepid
Fixed 5.2.6-0ubuntu3.1
released
jaunty
Fixed 5.2.6-0ubuntu5.1
released
karmic
Fixed 5.2.6-0ubuntu6.1
released
php4
dapper
ignored
feisty
dne
gutsy
dne
hardy
dne
intrepid
dne
jaunty
dne
karmic
dne
php5
dapper
Fixed 5.1.2-1ubuntu3.12
released
feisty
Fixed 5.2.1-0ubuntu1.6
released
gutsy
Fixed 5.2.3-1ubuntu6.4
released
hardy
Fixed 5.2.4-2ubuntu5.3
released
intrepid
not-affected
jaunty
not-affected
karmic
not-affected
References