MEDIUM
php: DoS via unserialize
Published Dec 24, 2009
5.0
MEDIUMCVSS 2.0
EPSS 0.97%
Description
The unserialize function in PHP 5.3.0 and earlier allows context-dependent attackers to cause a denial of service (resource consumption) via a deeply nested serialized variable, as demonstrated by a string beginning with a:1: followed by many {a:1: sequences.
Affected products
No data.
OR
- ≤ 5.3.0
- 5
- 5.0
- 5.0
- 5.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.1
- 5.0.2
- 5.0.3
- 5.0.4
- 5.0.5
- 5.1.0
- 5.1.1
- 5.1.2
- 5.1.3
- 5.1.4
- 5.1.5
- 5.1.6
- 5.2.0
- 5.2.1
- 5.2.2
- 5.2.3
- 5.2.4
- 5.2.4
- 5.2.5
- 5.2.6
- 5.2.7
- 5.2.8
- 5.2.9
- 5.2.10
- 5.2.11
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat does not consider this to be a security flaw. For further details, see https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-4418
Weaknesses (1)
References (7)
- http://www.suspekt.org/2009/11/28/shocking-news-in-php-exploitation/ x_refsource_MISC
- http://www.suspekt.org/downloads/POC2009-ShockingNewsInPHPExploitation.pdf x_refsource_MISC
- https://access.redhat.com/security/cve/CVE-2009-4418 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=550387 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-4385 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-4418
- https://www.cve.org/CVERecord?id=CVE-2009-4418
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 24, 2009
Updated Sep 17, 2024
Reserved Dec 24, 2009
Link CVE-2009-4418
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2009-4385 Assigner mitre
Published Dec 24, 2009
Updated Sep 17, 2024
Exploited since n/a
Link EUVD-2009-4385