5
CVSSv2

CVE-2015-4024

Published: 09/06/2015 Updated: 27/12/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP prior to 5.4.41, 5.5.x prior to 5.5.25, and 5.6.x prior to 5.6.9 allows remote malicious users to cause a denial of service (CPU consumption) via crafted form data that triggers an improper order-of-growth outcome.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise linux 7.0

redhat enterprise linux 6.0

apple mac os x

php php 5.5.0

php php 5.5.1

php php 5.5.19

php php 5.5.2

php php 5.5.4

php php 5.5.5

php php 5.6.0

php php 5.6.5

php php 5.6.6

php php

php php 5.5.10

php php 5.5.11

php php 5.5.20

php php 5.5.21

php php 5.5.6

php php 5.5.7

php php 5.5.8

php php 5.6.7

php php 5.6.8

php php 5.4.39

php php 5.5.12

php php 5.5.13

php php 5.5.22

php php 5.5.23

php php 5.6.2

php php 5.5.9

php php 5.5.14

php php 5.5.18

php php 5.5.24

php php 5.5.3

php php 5.6.3

php php 5.6.4

hp system management homepage

oracle linux 6

oracle solaris 11.2

oracle linux 7

redhat enterprise linux desktop 7.0

redhat enterprise linux server eus 7.1

redhat enterprise linux hpc node eus 7.1

redhat enterprise linux workstation 7.0

redhat enterprise linux server 7.0

redhat enterprise linux hpc node 7.0

Vendor Advisories

Several security issues were fixed in PHP ...
Multiple vulnerabilities have been discovered in PHP: CVE-2015-4025 / CVE-2015-4026 Multiple function didn't check for NULL bytes in path names CVE-2015-4024 Denial of service when processing multipart/form-data requests CVE-2015-4022 Integer overflow in the ftp_genlist() function may result in denial of service or potentiall ...
An integer underflow flaw leading to out-of-bounds memory access was found in the way PHP's Phar extension parsed Phar archives A specially crafted archive could cause PHP to crash or, possibly, execute arbitrary code when opened (CVE-2015-4021) An integer overflow flaw leading to a heap based buffer overflow was found in the way PHP's FTP extens ...
An integer underflow flaw leading to out-of-bounds memory access was found in the way PHP's Phar extension parsed Phar archives A specially crafted archive could cause PHP to crash or, possibly, execute arbitrary code when opened (CVE-2015-4021) An integer overflow flaw leading to a heap based buffer overflow was found in the way PHP's FTP extens ...
An integer underflow flaw leading to out-of-bounds memory access was found in the way PHP's Phar extension parsed Phar archives A specially crafted archive could cause PHP to crash or, possibly, execute arbitrary code when opened (CVE-2015-4021) An integer overflow flaw leading to a heap based buffer overflow was found in the way PHP's FTP extens ...
SecurityCenter is potentially impacted by several vulnerabilities in PHP that were recently disclosed and fixed Note that due to the time involved in doing a full analysis of each issue, Tenable has opted to patch the included version of PHP as a precaution, and to save time CVE-2015-4025: PHP Multiple NULL Byte Injection Filter Bypass Weaknesse ...

Github Repositories

CVE 2015-4024 , bug #69364 , multi process php load test

php-load-test CVE 2015-4024 , bug #69364 , multi process php load test WARNING: USE THIS TOOL AT YOUR OWN RISK 注意:此工具造成的任何后果由使用者自行承担 Usage: python xxxpy -t "TARGET_URL" -x "THREAD" -r "REQUEST_LENGTH" Example: python xxxpy -t "yoursiteusingphp/" -x "100" -r "35000

69364 PHP Multipart/form-data remote dos Vulnerability

php-bug-69364-test CVE 2015-4024 , bug #69364 PHP Multipart/form-data remote dos Vulnerability WARNING: USE THIS TOOL AT YOUR OWN RISK 注意:此工具造成的任何后果由使用者自行承担 原理:dropswooyunorg/papers/6077 官方:bugsphpnet/bugphp?id=69364 检测:portalnsfocuscom/vulnerability/list/ Usage: python xxxpy -t "http: