CVE-2003-0860
Description
Buffer overflows in PHP before 4.3.3 have unknown impact and unknown attack vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
26cpe:2.3:a:php:php:4.0:*:*:*:*:*:*:*+ 25 more
- cpe:2.3:a:php:php:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.0.1:patch1:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.0.1:patch2:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.0.3:patch1:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.0.7:rc1:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.0.7:rc2:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.0.7:rc3:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.2:*:dev:*:*:*:*:*
- cpe:2.3:a:php:php:4.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.3.2:*:*:*:*:*:*:*
- (no CPE)range: <4.3.3
Patches
Vulnerability mechanics
Root cause
"The bundle does not identify a specific root cause; the changelog entry only states that buffer overflows exist in PHP before 4.3.3."
Attack vector
The advisory (ref_id=1) explicitly states that the attack vectors are unknown. No network path, payload shape, or preconditions are described in the bundle.
Affected code
The PHP 4.3.3 changelog entry (ref_id=1) states only 'Buffer overflows in PHP before 4.3.3 have unknown impact and unknown attack vectors.' No specific functions, files, or code paths are identified in the bundle.
What the fix does
The bundle does not contain a patch diff. The only remediation reference is the PHP 4.3.3 release entry (ref_id=1), which lists 'Buffer overflows' as fixed but provides no code-level explanation of the changes.
Generated on Jun 16, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
2- www.php.net/release_4_3_3.phpnvdVendor Advisory
- www.php.net/ChangeLog-4.phpnvd
News mentions
0No linked articles in our index yet.