PT-2018-4564 · Php+3 · Php+3

Andreas Schnederle-Wagner

·

Published

2018-02-19

·

Updated

2022-11-18

·

CVE-2015-9253

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions PHP versions prior to 7.3.0alpha3 PHP versions prior to 7.2.8 PHP versions prior to 7.1.20
Description An issue was discovered where the php-fpm master process restarts a child process in an endless loop when using program execution functions (e.g., passthru, exec, shell exec, or system) with a non-blocking STDIN stream. This causes the master process to consume 100% of the CPU and generate a large volume of error logs, consuming disk space. An example of this issue was demonstrated by an attack on a customer of a shared-hosting facility.
Recommendations For PHP versions prior to 7.3.0alpha3, update to version 7.3.0alpha3 or later to resolve the issue. For PHP versions prior to 7.2.8, update to version 7.2.8 or later to resolve the issue. For PHP versions prior to 7.1.20, update to version 7.1.20 or later to resolve the issue.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2077
CVE-2015-9253
OPENSUSE-SU-2022_0679-1
OPENSUSE-SU-2022_4067-1
SUSE-SU-2022:0577-1
SUSE-SU-2022:0679-1
SUSE-SU-2022:4067-1
SUSE-SU-2022_0577-1
SUSE-SU-2022_0679-1
USN-3766-1
USN-4279-1
USN-4279-2
USN-5300-1

Affected Products

Alt Linux
Php
Suse
Ubuntu