Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37357
HistorySep 30, 2022 - 11:08 a.m.

Denial Of Service (DoS)

2022-09-3011:08:30
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17
php
vulnerability
infinite loop
system resource
uncompressor

0.0005 Low

EPSS

Percentile

18.1%

php is vulnerable to Denial Of Service (DoS). The vulnerability exists due to the phar uncompressor code which recursively uncompress quines gzip files, resulting in an infinite loop and deplete the system resource.