PT-2018-4564 · Php+3 · Php+3

Andreas Schnederle-Wagner

·

Publicado

2018-02-19

·

Atualizado

2022-11-18

·

CVE-2015-9253

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions PHP versions prior to 7.3.0alpha3 PHP versions prior to 7.2.8 PHP versions prior to 7.1.20
Description An issue was discovered where the php-fpm master process restarts a child process in an endless loop when using program execution functions (e.g., passthru, exec, shell exec, or system) with a non-blocking STDIN stream. This causes the master process to consume 100% of the CPU and generate a large volume of error logs, consuming disk space. An example of this issue was demonstrated by an attack on a customer of a shared-hosting facility.
Recommendations For PHP versions prior to 7.3.0alpha3, update to version 7.3.0alpha3 or later to resolve the issue. For PHP versions prior to 7.2.8, update to version 7.2.8 or later to resolve the issue. For PHP versions prior to 7.1.20, update to version 7.1.20 or later to resolve the issue.

Exploit

Correção

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2077
CVE-2015-9253
OPENSUSE-SU-2022_0679-1
OPENSUSE-SU-2022_4067-1
SUSE-SU-2022:0577-1
SUSE-SU-2022:0679-1
SUSE-SU-2022:4067-1
SUSE-SU-2022_0577-1
SUSE-SU-2022_0679-1
USN-3766-1
USN-4279-1
USN-4279-2
USN-5300-1

Produtos afetados

Alt Linux
Php
Suse
Ubuntu