CVE-2006-4812 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 20.4% (pctl 97)
Patch early
A public exploit exists.
Description
Integer overflow in PHP 5 up to 5.1.6 and 4 before 4.3.0 allows remote attackers to execute arbitrary code via an argument to the unserialize PHP function with a large value for the number of array elements, which triggers the overflow in the Zend Engine ecalloc function (Zend/zend_alloc.c).
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 20.38% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-10-10 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| php | php |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | PHP 3 < 5 - ZendEngine ECalloc Integer Overflow | 2006-10-05 |
References
- http://cvs.php.net/viewvc.cgi/ZendEngine2/zend_alloc.c?r1=1.161&r2=1.162
- http://lists.suse.com/archive/suse-security-announce/2006-Oct/0002.html
- http://rhn.redhat.com/errata/RHSA-2006-0688.html
- http://rhn.redhat.com/errata/RHSA-2006-0708.html
- http://secunia.com/advisories/22280
- http://secunia.com/advisories/22281
- http://secunia.com/advisories/22300
- http://secunia.com/advisories/22331
- http://secunia.com/advisories/22338
- http://secunia.com/advisories/22533
- http://secunia.com/advisories/22538
- http://secunia.com/advisories/22650
- http://securityreason.com/securityalert/1691
- http://securitytracker.com/id?1016984
- http://support.avaya.com/elmodocs2/security/ASA-2006-223.htm
- http://support.avaya.com/elmodocs2/security/ASA-2006-234.htm
- http://www.gentoo.org/security/en/glsa/glsa-200610-14.xml
- http://www.hardened-php.net/advisory_092006.133.html
- http://www.hardened-php.net/files/CVE-2006-4812.patch
- http://www.securityfocus.com/archive/1/448014/100/0/threaded
→ the Explorer · watch your stack · NVD