CVE-2007-4840

Source
https://cve.org/CVERecord?id=CVE-2007-4840
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2007-4840.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2007-4840
Downstream
Published
2007-09-12T20:17:00Z
Modified
2026-04-10T03:39:12.576012Z
Summary
[none]
Details

PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via (1) a long string in the outcharset parameter to the iconv function; or a long string in the charset parameter to the (2) iconvmimedecodeheaders, (3) iconvmimedecode, or (4) iconv_strlen function. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless these issues can be demonstrated for code execution.

References

Affected packages