PT-2024-3030 · Php+2 · Php+2
Benjamin Gehrels
+1
·
Published
2024-04-11
·
Updated
2025-08-11
·
CVE-2024-2757
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
PHP versions 8.3.0 through 8.3.4
Description
The issue is related to the function
mb encode mimeheader() in PHP, which can run endlessly for certain inputs containing long strings of non-space characters followed by a space. This could lead to a potential DoS attack if a hostile user sends data to an application that uses this function.Recommendations
For PHP versions 8.3.0 through 8.3.4, update to version 8.3.5 or later to resolve the issue.
As a temporary workaround, consider disabling the use of the
mb encode mimeheader() function in applications until a patch is available.Fix
DoS
Resource Exhaustion
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Php
Red Os