Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-4024

Опубликовано: 09 июн. 2015
Источник: debian
EPSS Средний

Описание

Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU consumption) via crafted form data that triggers an improper order-of-growth outcome.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php5fixed5.6.9+dfsg-1package
php5no-dsasqueezepackage
hhvmfixed3.11.0+dfsg-1package

Примечания

  • https://bugs.php.net/bug.php?id=69364

  • https://www.openwall.com/lists/oss-security/2015/05/18/2

  • Fixed upstream in 5.4.41, 5.5.25, 5.6.9

  • HHVM fix: https://github.com/facebook/hhvm/commit/6188457bd90ed2f3516e778dca8e91536d91802e

EPSS

Процентиль: 98%
0.68426
Средний

Связанные уязвимости

ubuntu
около 10 лет назад

Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU consumption) via crafted form data that triggers an improper order-of-growth outcome.

redhat
около 10 лет назад

Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU consumption) via crafted form data that triggers an improper order-of-growth outcome.

nvd
около 10 лет назад

Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU consumption) via crafted form data that triggers an improper order-of-growth outcome.

github
около 3 лет назад

Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU consumption) via crafted form data that triggers an improper order-of-growth outcome.

CVSS3: 4
fstec
около 10 лет назад

Уязвимость функции multipart_buffer_headers интерпретатора языка программирования PHP, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 98%
0.68426
Средний