6.8
CVSSv2

CVE-2015-9253

Published: 19/02/2018 Updated: 19/02/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:C

Vulnerability Summary

An issue exists in PHP 7.3.x prior to 7.3.0alpha3, 7.2.x prior to 7.2.8, and prior to 7.1.20. The php-fpm master process restarts a child process in an endless loop when using program execution functions (e.g., passthru, exec, shell_exec, or system) with a non-blocking STDIN stream, causing this master process to consume 100% of the CPU, and consume disk space with a large volume of error logs, as demonstrated by an attack by a customer of a shared-hosting facility.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

php php 7.3.0

php php

Vendor Advisories

Several security issues were fixed in PHP ...
Several security issues were fixed in PHP ...
Several security issues were fixed in PHP ...
USN-4279-1 introduced a regression in PHP ...
Several security issues were fixed in PHP ...
Several security issues were fixed in PHP ...
An issue was discovered in PHP 73x before 730alpha3, 72x before 728, and before 7120 The php-fpm master process restarts a child process in an endless loop when using program execution functions (eg, passthru, exec, shell_exec, or system) with a non-blocking STDIN stream, causing this master process to consume 100% of the CPU, and cons ...
An issue was discovered in PHP through 722 The php-fpm master process restarts a child process in an endless loop when using program execution functions (eg, passthru, exec, shell_exec, or system) with a non-blocking STDIN stream, causing this master process to consume 100% of the CPU, and consume disk space with a large volume of error logs, ...