Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-0662

Опубликовано: 16 фев. 2023
Источник: debian
EPSS Низкий

Описание

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consumption and excessive number of log entries. This can cause denial of service on the affected server by exhausting CPU resources or disk space.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php8.2fixed8.2.4-1package
php7.4removedpackage
php7.3removedpackage

Примечания

  • Fixed in: 8.2.3

  • https://github.com/php/php-src/security/advisories/GHSA-54hq-v5wp-fqgv

  • https://github.com/php/php-src/commit/716de0cff539f46294ef70fe75d548cd66766370

  • https://github.com/php/php-src/commit/e45850c195dcd5534394cf357a3f776d4916b655 (improvement)

EPSS

Процентиль: 29%
0.001
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consumption and excessive number of log entries. This can cause denial of service on the affected server by exhausting CPU resources or disk space.

CVSS3: 7.5
redhat
почти 3 года назад

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consumption and excessive number of log entries. This can cause denial of service on the affected server by exhausting CPU resources or disk space.

CVSS3: 7.5
nvd
почти 3 года назад

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consumption and excessive number of log entries. This can cause denial of service on the affected server by exhausting CPU resources or disk space.

CVSS3: 7.5
msrc
почти 3 года назад

DoS vulnerability when parsing multipart request body

CVSS3: 7.5
github
почти 3 года назад

DoS vulnerability when parsing multipart request body

EPSS

Процентиль: 29%
0.001
Низкий