CVE-2008-0599
9.8
CRITICAL · CVSS 3.1 · EPSS 10.9% (pctl 96)
Patch early
EPSS 10.9% — above the 10% action threshold.
Description
The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 10.92% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-131 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2008-05-05 |
| Last modified | 2026-06-16 |
Affected (5)
| Vendor | Product |
|---|---|
| apple | mac os x |
| apple | mac os x server |
| canonical | ubuntu linux |
| fedoraproject | fedora |
| php | php |
References
- http://cvs.php.net/viewvc.cgi/php-src/sapi/cgi/cgi_main.c?r1=1.267.2.15.2.50.2.12&r2=1.267.2.15.2.50.2.13&diff_format=u
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01476437
- http://lists.apple.com/archives/security-announce//2008/Jul/msg00003.html
- http://marc.info/?l=bugtraq&m=124654546101607&w=2
- http://marc.info/?l=bugtraq&m=125631037611762&w=2
- http://secunia.com/advisories/30048
- http://secunia.com/advisories/30083
- http://secunia.com/advisories/30345
- http://secunia.com/advisories/30616
- http://secunia.com/advisories/30757
- http://secunia.com/advisories/30828
- http://secunia.com/advisories/31200
- http://secunia.com/advisories/31326
- http://secunia.com/advisories/32746
- http://secunia.com/advisories/35650
- http://security.gentoo.org/glsa/glsa-200811-05.xml
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0176
- http://www.kb.cert.org/vuls/id/147027
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:127
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:128
→ the Explorer · watch your stack · NVD