PT-2018-13061 · Swoole · Swoole
Publicado
2018-08-18
·
Atualizado
2018-11-08
·
CVE-2018-15503
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Swoole version 4.0.4
Description
The issue is related to the unpack implementation in the deserialization process, which lacks correct size checks. This allows an attacker to craft a malicious serialized object, potentially leading to exploitation and causing a segmentation fault (SEGV).
Recommendations
For Swoole version 4.0.4, consider updating to a newer version that addresses this issue, as the current version lacks proper size checks in its deserialization process. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Deserialization of Untrusted Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Swoole