Buffer underflow in the header function in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by passing an all-whitespace string to this function, which causes it to write '\0' characters in whitespace that precedes the string.
| Software | From | Fixed in |
|---|---|---|
| php / php | 5.2.0 | 5.2.0.x |