PHP 'getimagesize()' Remote Denial Of Service Vulnerability
BID:53289
Info
PHP 'getimagesize()' Remote Denial Of Service Vulnerability
| Bugtraq ID: | 53289 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 29 2012 12:00AM |
| Updated: | Apr 29 2012 12:00AM |
| Credit: | Manuel Fernández and Francisco Oca |
| Vulnerable: |
PHP PHP 5.4.1 PHP PHP 5.3.9 PHP PHP 5.3.8 PHP PHP 5.3.7 PHP PHP 5.3.6 PHP PHP 5.3.6 PHP PHP 5.3.5 PHP PHP 5.3.2 PHP PHP 5.3.1 PHP PHP 5.3 PHP PHP 5.2.17 PHP PHP 5.2.15 PHP PHP 5.2.13 PHP PHP 5.2.12 PHP PHP 5.2.11 PHP PHP 5.2.10 PHP PHP 5.2.9 -2 PHP PHP 5.2.9 PHP PHP 5.2.8 PHP PHP 5.2.7 PHP PHP 5.2.6 PHP PHP 5.2.5 PHP PHP 5.2.4 PHP PHP 5.2.3 PHP PHP 5.2.2 PHP PHP 5.2.1 PHP PHP 5.1.6 PHP PHP 5.1.5 PHP PHP 5.1.4 PHP PHP 5.1.3 -RC1 PHP PHP 5.1.3 PHP PHP 5.1.2 PHP PHP 5.1.1 PHP PHP 5.1 PHP PHP 5.0.5 PHP PHP 5.0.4 PHP PHP 5.0.3 PHP PHP 5.0.2 PHP PHP 5.0.1 PHP PHP 5.3.5 PHP PHP 5.3.4 RC1 PHP PHP 5.3.4 PHP PHP 5.3.3 PHP PHP 5.3.10 PHP PHP 5.2.14 PHP PHP 5.2 |
| Not Vulnerable: | |
Discussion
PHP 'getimagesize()' Remote Denial Of Service Vulnerability
PHP is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to exhaust available resources, causing a denial-of-service condition.
PHP versions 5.4.1 and prior are vulnerable.
PHP is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to exhaust available resources, causing a denial-of-service condition.
PHP versions 5.4.1 and prior are vulnerable.
Exploit / POC
PHP 'getimagesize()' Remote Denial Of Service Vulnerability
Attackers can use standard, readily available tools to exploit this issue.
Attackers can use standard, readily available tools to exploit this issue.
Solution / Fix
PHP 'getimagesize()' Remote Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
References
PHP 'getimagesize()' Remote Denial Of Service Vulnerability
References:
References: