Back

HIGH

php: DoS (memory exhaustion, application crash) via crafted function definition

Published May 31, 2013

Description

The Zend Engine in PHP before 5.4.16 RC1, and 5.5.0 before RC2, does not properly determine whether a parser error occurred, which allows context-dependent attackers to cause a denial of service (memory consumption and application crash) via a crafted function definition, as demonstrated by an attack within a shared web-hosting environment. NOTE: the vendor's http://php.net/security-note.php page says "for critical security situations you should be using OS-level security by running multiple web servers each as their own user id.

Affected products

Remediation

Red Hat statement

We do not consider memory safety hazards caused by malformed php scripts as a security issue. Also (as per upstream) OS-level security should be used to protect systems from memory exhaustion caused by php applications.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 31, 2013
Updated Jan 16, 2025
Reserved May 31, 2013
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date May 23, 2013