Description
PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, which allows remote attackers to cause a denial of service (resource exhaustion), and makes it easier for remote attackers to exploit local file inclusion vulnerabilities, via multiple requests, related to lack of support for the max_file_uploads directive.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Ubuntu USN |
USN-862-1 | PHP vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T06:45:50.952Z
Reserved: 2009-11-20T00:00:00.000Z
Link: CVE-2009-4017
No data.
Status : Modified
Published: 2009-11-24T00:30:00.500
Modified: 2026-04-23T00:35:47.467
Link: CVE-2009-4017
OpenCVE Enrichment
No data.
Weaknesses
Ubuntu USN