Back

MEDIUM

php: DoS via unserialize

Published Dec 24, 2009

Description

The unserialize function in PHP 5.3.0 and earlier allows context-dependent attackers to cause a denial of service (resource consumption) via a deeply nested serialized variable, as demonstrated by a string beginning with a:1: followed by many {a:1: sequences.

Affected products

Remediation

Red Hat statement

Red Hat does not consider this to be a security flaw. For further details, see https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-4418

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 24, 2009
Updated Sep 17, 2024
Reserved Dec 24, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Nov 5, 2009
ENISA EUVD
Assigner mitre
Published Dec 24, 2009
Updated Sep 17, 2024
Exploited since n/a
EUVD-2009-4385