Buffer overflow in the crack extension (CrackLib), as bundled with PHP 4.4.6 and other versions before 5.0.0, might allow local users to gain privileges via a long argument to the crack_opendict function.Referenceshttp://retrogod.altervista.org/php_446_crack_opendict_local_bof.htmlhttps://www.exploit-db.com/exploits/3431http://securityreason.com/securityalert/2405http://www.securityfocus.com/archive/1/462226/100/0/threaded