Input validation error in PHP - CVE-2007-0909

 

Input validation error in PHP - CVE-2007-0909

Published: October 30, 2018 / Updated: June 8, 2025


Vulnerability identifier: #VU110462
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2007-0909
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Multiple format string vulnerabilities in PHP before 5.2.1 might allow attackers to execute arbitrary code via format string specifiers to (1) all of the *print functions on 64-bit systems, and (2) the odbc_result_all function.


Affected software

PHP
Gentoo Linux
dev-lang/php

How to mitigate CVE-2007-0909

Install update from vendor's website.

PHP - addressed in versions 4.4.5, 4.10, 5.2.0
dev-lang/php - update to 5.2.1-r3

External References

Related Security Bulletins