CVE-2007-4658

Description

From CVE.org

The money_format function in PHP 5 before 5.2.4, and PHP 4 before 4.4.8, permits multiple (1) %i and (2) %n tokens, which has unknown impact and attack vectors, possibly related to a format string vulnerability.

Statement

This issue did not affect the versions of PHP as shipped with Red Hat Enterprise Linux 2.1.

Frequently Asked Questions

Want to get errata notifications? Sign up here.