Input validation error in PHP - CVE-2007-2509
Published: October 30, 2018 / Updated: June 8, 2025
Vulnerability identifier: #VU110402
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2007-2509
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: PHP Group
Affected software:
PHP
PHP
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to corrupt data.
CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands.
How to mitigate CVE-2007-2509
Install update from vendor's website.
Sources
- http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html
- http://rhn.redhat.com/errata/RHSA-2007-0889.html
- http://secunia.com/advisories/25187
- http://secunia.com/advisories/25191
- http://secunia.com/advisories/25255
- http://secunia.com/advisories/25318
- http://secunia.com/advisories/25365
- http://secunia.com/advisories/25372
- http://secunia.com/advisories/25445
- http://secunia.com/advisories/25660
- http://secunia.com/advisories/26048
- http://secunia.com/advisories/26967
- http://secunia.com/advisories/27351
- http://security.gentoo.org/glsa/glsa-200705-19.xml
- http://securityreason.com/securityalert/2672
- http://support.avaya.com/elmodocs2/security/ASA-2007-231.htm
- http://us2.php.net/releases/4_4_7.php
- http://us2.php.net/releases/5_2_2.php
- http://www.debian.org/security/2007/dsa-1295
- http://www.debian.org/security/2007/dsa-1296
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:102
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:103
- http://www.redhat.com/support/errata/RHSA-2007-0349.html
- http://www.redhat.com/support/errata/RHSA-2007-0355.html
- http://www.redhat.com/support/errata/RHSA-2007-0888.html
- http://www.securityfocus.com/archive/1/463596/100/0/threaded
- http://www.securityfocus.com/bid/23813
- http://www.securityfocus.com/bid/23818
- http://www.securitytracker.com/id?1018022
- http://www.trustix.org/errata/2007/0017/
- http://www.ubuntu.com/usn/usn-462-1
- http://www.vupen.com/english/advisories/2007/2187
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34413
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10839
- https://rhn.redhat.com/errata/RHSA-2007-0348.html