PHPBB BBCode Denial Of Service Vulnerability
BID:4434
Info
PHPBB BBCode Denial Of Service Vulnerability
| Bugtraq ID: | 4434 |
| Class: | Design Error |
| CVE: |
CVE-2002-0533 CVE-2002-0533 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 04 2002 12:00AM |
| Updated: | Mar 19 2015 09:32AM |
| Credit: | Discovery is credited to Whitecell Security Systems <[email protected]>. |
| Vulnerable: |
phpBB Group phpBB 1.4.4 phpBB Group phpBB 1.4.2 phpBB Group phpBB 1.4.1 phpBB Group phpBB 1.4 .0 phpBB Group phpBB 1.2.1 phpBB Group phpBB 1.2 .0 phpBB Group phpBB 1.0 .0 |
| Not Vulnerable: | |
Discussion
PHPBB BBCode Denial Of Service Vulnerability
phpBB is free, open-source web forums software that is written in PHP and backended by MySQL. It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems.
A vulnerability exists in phpBB's implementation of BBcode which makes it possible for an attacker to starve resources on the host running the affected software. This may result in a denial of service to the webserver and possibly the underlying system if adequate resource limits are not in place.
If this issue is successfully exploited, the webserver will need to be restarted for normal functionality to resume.
phpBB is free, open-source web forums software that is written in PHP and backended by MySQL. It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems.
A vulnerability exists in phpBB's implementation of BBcode which makes it possible for an attacker to starve resources on the host running the affected software. This may result in a denial of service to the webserver and possibly the underlying system if adequate resource limits are not in place.
If this issue is successfully exploited, the webserver will need to be restarted for normal functionality to resume.
Exploit / POC
PHPBB BBCode Denial Of Service Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
PHPBB BBCode Denial Of Service Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHPBB BBCode Denial Of Service Vulnerability
References:
References: