CVE-2015-4024

medium HPE
CVSS v3 Base Score
5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS Score
75.5%
Exploitation probability in 30 days
Top 1% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Confidentiality
None
Integrity
None
Availability
P
Published: June 9, 2015 (3992 days ago)
Last Modified: May 6, 2026
Vendor: HPE
Source: NVD

Description

Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU consumption) via crafted form data that triggers an improper order-of-growth outcome.

CWE

CWE-399

Affected Products

redhat enterprise linuxapple mac os xphp phphp system management homepageoracle linuxoracle solarisredhat enterprise linux desktopredhat enterprise linux hpc noderedhat enterprise linux hpc node eusredhat enterprise linux server

References