PT-2018-13061 · Swoole · Swoole
Published
2018-08-18
·
Updated
2018-11-08
·
CVE-2018-15503
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Swoole version 4.0.4
Description
The issue is related to the unpack implementation in the deserialization process, which lacks correct size checks. This allows an attacker to craft a malicious serialized object, potentially leading to exploitation and causing a segmentation fault (SEGV).
Recommendations
For Swoole version 4.0.4, consider updating to a newer version that addresses this issue, as the current version lacks proper size checks in its deserialization process. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Swoole