High severity7.5NVD Advisory· Published Mar 6, 2007· Updated Apr 23, 2026
CVE-2007-1285
CVE-2007-1285
Description
The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.
Affected products
14- cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux:10.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:novell:suse_linux:10.0:*:*:*:*:*:*:*
- cpe:2.3:o:novell:suse_linux:10.1:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:3.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_desktop:3.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_desktop:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:2.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:redhat:enterprise_linux_server:2.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server:3.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:2.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:redhat:enterprise_linux_workstation:2.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_workstation:3.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_workstation:4.0:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:10:sp1:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:suse:linux_enterprise_server:10:sp1:*:*:*:*:*:*
- cpe:2.3:o:suse:linux_enterprise_server:8:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
38- www.php-security.org/MOPB/MOPB-03-2007.htmlnvdBroken LinkExploitVendor Advisory
- launchpad.net/bugs/173043nvdExploitIssue Tracking
- rhn.redhat.com/errata/RHSA-2007-0154.htmlnvdThird Party Advisory
- rhn.redhat.com/errata/RHSA-2007-0155.htmlnvdThird Party Advisory
- secunia.com/advisories/24909nvdBroken LinkVendor Advisory
- secunia.com/advisories/24910nvdBroken LinkVendor Advisory
- secunia.com/advisories/24924nvdBroken LinkVendor Advisory
- secunia.com/advisories/24941nvdBroken LinkVendor Advisory
- secunia.com/advisories/24945nvdBroken LinkVendor Advisory
- secunia.com/advisories/25445nvdBroken LinkVendor Advisory
- secunia.com/advisories/26048nvdBroken LinkVendor Advisory
- secunia.com/advisories/26642nvdBroken LinkVendor Advisory
- secunia.com/advisories/27864nvdBroken LinkVendor Advisory
- secunia.com/advisories/28936nvdBroken LinkVendor Advisory
- security.gentoo.org/glsa/glsa-200705-19.xmlnvdThird Party Advisory
- www.mandriva.com/security/advisoriesnvdThird Party Advisory
- www.mandriva.com/security/advisoriesnvdThird Party Advisory
- www.mandriva.com/security/advisoriesnvdThird Party Advisory
- www.mandriva.com/security/advisoriesnvdThird Party Advisory
- www.securityfocus.com/archive/1/466166/100/0/threadednvdBroken LinkThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/22764nvdBroken LinkThird Party AdvisoryVDB Entry
- www.securitytracker.com/idnvdBroken LinkThird Party AdvisoryVDB Entry
- www.ubuntu.com/usn/usn-549-2nvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.htmlnvdMailing List
- rhn.redhat.com/errata/RHSA-2007-0163.htmlnvdBroken Link
- slackware.com/security/viewer.phpnvdBroken Link
- us2.php.net/releases/4_4_7.phpnvdRelease Notes
- us2.php.net/releases/5_2_2.phpnvdRelease Notes
- www.osvdb.org/32769nvdBroken Link
- www.php.net/ChangeLog-4.phpnvdRelease Notes
- www.php.net/ChangeLog-5.phpnvdRelease Notes
- www.php.net/releases/4_4_8.phpnvdRelease Notes
- www.php.net/releases/5_2_4.phpnvdRelease Notes
- www.redhat.com/support/errata/RHSA-2007-0082.htmlnvdBroken Link
- www.redhat.com/support/errata/RHSA-2007-0162.htmlnvdBroken Link
- issues.rpath.com/browse/RPL-1268nvdBroken Link
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11017nvdBroken Link
- usn.ubuntu.com/549-1/nvdBroken Link
News mentions
0No linked articles in our index yet.