Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-4024

Опубликовано: 14 мая 2015
Источник: redhat
CVSS2: 5
EPSS Средний

Описание

Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU consumption) via crafted form data that triggers an improper order-of-growth outcome.

A flaw was found in the way PHP parsed multipart HTTP POST requests. A specially crafted request could cause PHP to use an excessive amount of CPU time.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5phpWill not fix
Red Hat Enterprise Linux 5php53Will not fix
Red Hat Enterprise Linux 6phpFixedRHSA-2015:121809.07.2015
Red Hat Enterprise Linux 7phpFixedRHSA-2015:113523.06.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6php55-phpFixedRHSA-2015:118625.06.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-php56-phpFixedRHSA-2015:118725.06.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6php54-phpFixedRHSA-2015:121909.07.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUSphp55-phpFixedRHSA-2015:118625.06.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUSrh-php56-phpFixedRHSA-2015:118725.06.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUSphp54-phpFixedRHSA-2015:121909.07.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-407
https://bugzilla.redhat.com/show_bug.cgi?id=1222485php: multipart/form-data request parsing CPU usage DoS

EPSS

Процентиль: 98%
0.68426
Средний

5 Medium

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU consumption) via crafted form data that triggers an improper order-of-growth outcome.

nvd
около 10 лет назад

Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU consumption) via crafted form data that triggers an improper order-of-growth outcome.

debian
около 10 лет назад

Algorithmic complexity vulnerability in the multipart_buffer_headers f ...

github
около 3 лет назад

Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU consumption) via crafted form data that triggers an improper order-of-growth outcome.

CVSS3: 4
fstec
около 10 лет назад

Уязвимость функции multipart_buffer_headers интерпретатора языка программирования PHP, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 98%
0.68426
Средний

5 Medium

CVSS2