CVE-2015-9253
Summary
| CVE | CVE-2015-9253 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-19 19:29:00 UTC |
| Updated | 2020-02-19 00:15:00 UTC |
| Description | An issue was discovered in PHP 7.3.x before 7.3.0alpha3, 7.2.x before 7.2.8, and before 7.1.20. The php-fpm master process restarts a child process in an endless loop when using program execution functions (e.g., passthru, exec, shell_exec, or system) with a non-blocking STDIN stream, causing this master process to consume 100% of the CPU, and consume disk space with a large volume of error logs, as demonstrated by an attack by a customer of a shared-hosting facility. |
Risk And Classification
Problem Types: CWE-400
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| php-src/NEWS at PHP-7.1.20 · php/php-src · GitHub | CONFIRM | github.com | Third Party Advisory |
| USN-3766-1: PHP vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | Third Party Advisory |
| Fixed bug #73342 · php/php-src@69dee5c · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| php-fpm master process restarts child process in an endless loop when using Program execution Function (CVE-2015-9253) - Futureweb OG - St. Johann in Tirol | MISC | www.futureweb.at | Exploit, Third Party Advisory |
| PHP :: Sec Bug #73342 :: Vulnerability in php-fpm by changing stdin to non-blocking | CONFIRM | bugs.php.net | Exploit, Issue Tracking, Vendor Advisory |
| PHP :: Bug #75968 :: php-fpm restarts master process in a loop when using Program execution Function | MISC | bugs.php.net | Exploit, Issue Tracking, Vendor Advisory |
| USN-4279-1: PHP vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| PHP :: Bug #70185 :: php-fpm restarts master process in a loop when exec() and using ssh multiplexing | MISC | bugs.php.net | Exploit, Issue Tracking, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 501132 Alpine Linux Security Update for php7
- 751763 SUSE Enterprise Linux Security Update for php72 (SUSE-SU-2022:0577-1)
- 751772 SUSE Enterprise Linux Security Update for php7 (SUSE-SU-2022:0679-1)
- 751779 OpenSUSE Security Update for php7 (openSUSE-SU-2022:0679-1)
- 752878 SUSE Enterprise Linux Security Update for php7 (SUSE-SU-2022:4067-1)