CVE-2008-2829

php_imap.c in PHP 5.2.5, 5.2.6, 4.x, and other versions, uses obsolete API calls that allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long IMAP request, which triggers an "rfc822.c legacy routine buffer overflow" error message, related to the rfc822_write_address function.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
VendorProductVersion
phpphp
𝑥
≤ 4.4.9
phpphp
5.2.5
phpphp
5.2.6
canonicalubuntu_linux
6.06
canonicalubuntu_linux
7.04
canonicalubuntu_linux
7.10
canonicalubuntu_linux
8.04
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
php-imap
karmic
Fixed 5.2.6-0ubuntu6.1
released
jaunty
Fixed 5.2.6-0ubuntu5.1
released
intrepid
Fixed 5.2.6-0ubuntu3.1
released
hardy
Fixed 5.2.3-0ubuntu3.1
released
dapper
ignored
php4
karmic
dne
jaunty
dne
intrepid
dne
hardy
dne
gutsy
dne
feisty
dne
dapper
ignored
php5
karmic
not-affected
jaunty
not-affected
intrepid
not-affected
hardy
Fixed 5.2.4-2ubuntu5.3
released
gutsy
Fixed 5.2.3-1ubuntu6.4
released
feisty
Fixed 5.2.1-0ubuntu1.6
released
dapper
Fixed 5.1.2-1ubuntu3.12
released
References