PT-2017-18030 · Php+1 · Php+1

Whitehat002

·

Published

2017-04-19

·

Updated

2024-08-05

·

CVE-2017-7963

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions PHP versions through 7.1.4
Description The issue allows attackers to cause a denial of service via operations on long strings, resulting in memory consumption and application crash. The vendor disputes this, stating that GMP safely aborts in case of an OOM condition, and the only attack vector is denial of service. However, if attacker-controlled, unbounded allocations are allowed, there is a DoS vector regardless of GMP's OOM behavior.
Recommendations For PHP versions through 7.1.4, consider restricting the length of input strings to prevent unbounded allocations and minimize the risk of denial of service attacks. As a temporary workaround, monitor application memory consumption and implement measures to prevent excessive memory usage. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1610
CVE-2017-7963

Affected Products

Alt Linux
Php