Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11710
HistoryJan 15, 2019 - 9:06 a.m.

Denial Of Service (DoS)

2019-01-1509:06:33
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.74 High

EPSS

Percentile

98.1%

php is vulnerable to denial of service. A flaw was found in the way PHP parsed multipart HTTP POST requests. A specially crafted request could cause PHP to use an excessive amount of CPU time. An integer overflow flaw leading to a heap-based buffer overflow was found in the way PHP’s FTP extension parsed file listing FTP server responses. A malicious FTP server could use this flaw to cause a PHP application to crash or, possibly, execute arbitrary code.

References