CVE-2007-1900

Publication date 10 April 2007

Last updated 24 July 2024


Ubuntu priority

CRLF injection vulnerability in the FILTER_VALIDATE_EMAIL filter in ext/filter in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to inject arbitrary e-mail headers via an e-mail address with a '\n' character, which causes a regular expression to ignore the subsequent part of the address string.

Status

Package Ubuntu Release Status
php5 7.04 feisty
Fixed 5.2.1-0ubuntu1.4
6.10 edgy
Not affected
6.06 LTS dapper
Not affected

References

Related Ubuntu Security Notices (USN)

    • USN-455-1
    • PHP vulnerabilities
    • 27 April 2007

Other references