PT-2018-13061 · Swoole · Swoole

Publicado

2018-08-18

·

Atualizado

2018-11-08

·

CVE-2018-15503

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Swoole version 4.0.4
Description The issue is related to the unpack implementation in the deserialization process, which lacks correct size checks. This allows an attacker to craft a malicious serialized object, potentially leading to exploitation and causing a segmentation fault (SEGV).
Recommendations For Swoole version 4.0.4, consider updating to a newer version that addresses this issue, as the current version lacks proper size checks in its deserialization process. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-15503

Produtos afetados

Swoole