PT-2018-13061 · Swoole · Swoole

Published

2018-08-18

·

Updated

2018-11-08

·

CVE-2018-15503

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Swoole version 4.0.4
Description The issue is related to the unpack implementation in the deserialization process, which lacks correct size checks. This allows an attacker to craft a malicious serialized object, potentially leading to exploitation and causing a segmentation fault (SEGV).
Recommendations For Swoole version 4.0.4, consider updating to a newer version that addresses this issue, as the current version lacks proper size checks in its deserialization process. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-15503

Affected Products

Swoole