Описание
On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LPT1 to LPT9, CONIN$ and CONOUT$ when they appear as a component of a path. An attacker-controlled filename therefore reaches CreateFileW() and opens a device instead of the regular file the application expected, which can block or hang the request and exhaust worker processes.
A flaw was found in PHP. When running on Windows environments, PHP's filesystem and stream handlers fail to reject reserved system device names in file paths. An attacker who can control file or stream paths can supply these reserved names to open system devices instead of standard files. This can cause application worker processes to block or hang indefinitely, resulting in a Denial of Service (DoS) through resource exhaustion.
Отчет
This only affects Windows. Hence, this does not affect Red Hat products.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | php | Not affected | ||
| Red Hat Enterprise Linux 10 | php8.4 | Not affected | ||
| Red Hat Enterprise Linux 6 | php | Not affected | ||
| Red Hat Enterprise Linux 7 | php | Not affected | ||
| Red Hat Enterprise Linux 8 | php:7.4/php | Not affected | ||
| Red Hat Enterprise Linux 8 | php:8.2/php | Not affected | ||
| Red Hat Enterprise Linux 9 | php | Not affected | ||
| Red Hat Enterprise Linux 9 | php:8.2/php | Not affected | ||
| Red Hat Enterprise Linux 9 | php:8.3/php | Not affected | ||
| Red Hat Enterprise Linux 9 | php:8.4/php | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LPT1 to LPT9, CONIN$ and CONOUT$ when they appear as a component of a path. An attacker-controlled filename therefore reaches CreateFileW() and opens a device instead of the regular file the application expected, which can block or hang the request and exhaust worker processes.
On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LPT1 to LPT9, CONIN$ and CONOUT$ when they appear as a component of a path. An attacker-controlled filename therefore reaches CreateFileW() and opens a device instead of the regular file the application expected, which can block or hang the request and exhaust worker processes.
PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O which can cause DoS
On Windows, PHP's filesystem and stream APIs do not reject reserved de ...
PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O which can cause DoS
EPSS
5.9 Medium
CVSS3