CVE-2015-4024

Description

Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU consumption) via crafted form data that triggers an improper order-of-growth outcome.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS Score
Exploitation Probability
75.519

Associated Vulnerability

VulnerabilityOS Platform
Update HP System Management Homepage Detection (x64) 7.5.3.1 to latest versionWindows
Update HP System Management Homepage Detection 7.5.3.1 to latest versionWindows
Multiple vulnerabilities are fixed in OS X Yosemite 10.10.5 UpdateMac
Multiple vulnerabilities are fixed in OS X Yosemite 10.10.5 Combo UpdateMac
HTML-embedded scripting language interpreter (USN-2658-1) php5-cgi_5.6.4+dfsg-4ubuntu6.4_i386.debLinux
HTML-embedded scripting language interpreter (USN-2658-1) php5-cgi_5.6.4+dfsg-4ubuntu6.4_amd64.debLinux
HTML-embedded scripting language interpreter (USN-2658-1) php5-cli_5.6.4+dfsg-4ubuntu6.4_i386.debLinux
HTML-embedded scripting language interpreter (USN-2658-1) php5-cli_5.6.4+dfsg-4ubuntu6.4_amd64.debLinux
HTML-embedded scripting language interpreter (USN-2658-1) php5-fpm_5.6.4+dfsg-4ubuntu6.4_i386.debLinux
HTML-embedded scripting language interpreter (USN-2658-1) php5-fpm_5.6.4+dfsg-4ubuntu6.4_amd64.debLinux
HTML-embedded scripting language interpreter (USN-2658-1) libapache2-mod-php5_5.6.4+dfsg-4ubuntu6.4_i386.debLinux
HTML-embedded scripting language interpreter (USN-2658-1) libapache2-mod-php5_5.6.4+dfsg-4ubuntu6.4_amd64.debLinux
Php55-php update (ELSA-2015-1186) php55-php-5.5.21-4.el7.x86_64.rpmLinux
Php55-php-bcmath update (ELSA-2015-1186) php55-php-bcmath-5.5.21-4.el7.x86_64.rpmLinux
Php55-php-cli update (ELSA-2015-1186) php55-php-cli-5.5.21-4.el7.x86_64.rpmLinux
Php55-php-common update (ELSA-2015-1186) php55-php-common-5.5.21-4.el7.x86_64.rpmLinux
Php55-php-dba update (ELSA-2015-1186) php55-php-dba-5.5.21-4.el7.x86_64.rpmLinux
Php55-php-devel update (ELSA-2015-1186) php55-php-devel-5.5.21-4.el7.x86_64.rpmLinux
Php55-php-enchant update (ELSA-2015-1186) php55-php-enchant-5.5.21-4.el7.x86_64.rpmLinux
Php55-php-fpm update (ELSA-2015-1186) php55-php-fpm-5.5.21-4.el7.x86_64.rpmLinux
Php55-php-gd update (ELSA-2015-1186) php55-php-gd-5.5.21-4.el7.x86_64.rpmLinux
Php55-php-gmp update (ELSA-2015-1186) php55-php-gmp-5.5.21-4.el7.x86_64.rpmLinux
Php55-php-intl update (ELSA-2015-1186) php55-php-intl-5.5.21-4.el7.x86_64.rpmLinux
Php55-php-ldap update (ELSA-2015-1186) php55-php-ldap-5.5.21-4.el7.x86_64.rpmLinux
Php55-php-mbstring update (ELSA-2015-1186) php55-php-mbstring-5.5.21-4.el7.x86_64.rpmLinux
Php55-php-mysqlnd update (ELSA-2015-1186) php55-php-mysqlnd-5.5.21-4.el7.x86_64.rpmLinux
Php55-php-odbc update (ELSA-2015-1186) php55-php-odbc-5.5.21-4.el7.x86_64.rpmLinux
Php55-php-opcache update (ELSA-2015-1186) php55-php-opcache-5.5.21-4.el7.x86_64.rpmLinux
Php55-php-pdo update (ELSA-2015-1186) php55-php-pdo-5.5.21-4.el7.x86_64.rpmLinux
Php55-php-pgsql update (ELSA-2015-1186) php55-php-pgsql-5.5.21-4.el7.x86_64.rpmLinux
Php55-php-process update (ELSA-2015-1186) php55-php-process-5.5.21-4.el7.x86_64.rpmLinux
Php55-php-pspell update (ELSA-2015-1186) php55-php-pspell-5.5.21-4.el7.x86_64.rpmLinux
Php55-php-recode update (ELSA-2015-1186) php55-php-recode-5.5.21-4.el7.x86_64.rpmLinux
Php55-php-snmp update (ELSA-2015-1186) php55-php-snmp-5.5.21-4.el7.x86_64.rpmLinux
Php55-php-soap update (ELSA-2015-1186) php55-php-soap-5.5.21-4.el7.x86_64.rpmLinux
Php55-php-xml update (ELSA-2015-1186) php55-php-xml-5.5.21-4.el7.x86_64.rpmLinux
Php55-php-xmlrpc update (ELSA-2015-1186) php55-php-xmlrpc-5.5.21-4.el7.x86_64.rpmLinux
Php54-php update (ELSA-2015-1219) php54-php-5.4.40-3.el6.x86_64.rpmLinux
Php54-php-bcmath update (ELSA-2015-1219) php54-php-bcmath-5.4.40-3.el6.x86_64.rpmLinux
Php54-php-cli update (ELSA-2015-1219) php54-php-cli-5.4.40-3.el6.x86_64.rpmLinux
Php54-php-common update (ELSA-2015-1219) php54-php-common-5.4.40-3.el6.x86_64.rpmLinux
Php54-php-dba update (ELSA-2015-1219) php54-php-dba-5.4.40-3.el6.x86_64.rpmLinux
Php54-php-devel update (ELSA-2015-1219) php54-php-devel-5.4.40-3.el6.x86_64.rpmLinux
Php54-php-enchant update (ELSA-2015-1219) php54-php-enchant-5.4.40-3.el6.x86_64.rpmLinux
Php54-php-fpm update (ELSA-2015-1219) php54-php-fpm-5.4.40-3.el6.x86_64.rpmLinux
Php54-php-gd update (ELSA-2015-1219) php54-php-gd-5.4.40-3.el6.x86_64.rpmLinux
Php54-php-imap update (ELSA-2015-1219) php54-php-imap-5.4.40-3.el6.x86_64.rpmLinux
Php54-php-intl update (ELSA-2015-1219) php54-php-intl-5.4.40-3.el6.x86_64.rpmLinux
Php54-php-ldap update (ELSA-2015-1219) php54-php-ldap-5.4.40-3.el6.x86_64.rpmLinux
Php54-php-mbstring update (ELSA-2015-1219) php54-php-mbstring-5.4.40-3.el6.x86_64.rpmLinux
Php54-php-mysqlnd update (ELSA-2015-1219) php54-php-mysqlnd-5.4.40-3.el6.x86_64.rpmLinux
Php54-php-odbc update (ELSA-2015-1219) php54-php-odbc-5.4.40-3.el6.x86_64.rpmLinux
Php54-php-pdo update (ELSA-2015-1219) php54-php-pdo-5.4.40-3.el6.x86_64.rpmLinux
Php54-php-pgsql update (ELSA-2015-1219) php54-php-pgsql-5.4.40-3.el6.x86_64.rpmLinux
Php54-php-process update (ELSA-2015-1219) php54-php-process-5.4.40-3.el6.x86_64.rpmLinux
Php54-php-pspell update (ELSA-2015-1219) php54-php-pspell-5.4.40-3.el6.x86_64.rpmLinux
Php54-php-recode update (ELSA-2015-1219) php54-php-recode-5.4.40-3.el6.x86_64.rpmLinux
Php54-php-snmp update (ELSA-2015-1219) php54-php-snmp-5.4.40-3.el6.x86_64.rpmLinux
Php54-php-soap update (ELSA-2015-1219) php54-php-soap-5.4.40-3.el6.x86_64.rpmLinux
Php54-php-tidy update (ELSA-2015-1219) php54-php-tidy-5.4.40-3.el6.x86_64.rpmLinux
Php54-php-xml update (ELSA-2015-1219) php54-php-xml-5.4.40-3.el6.x86_64.rpmLinux
Php54-php-xmlrpc update (ELSA-2015-1219) php54-php-xmlrpc-5.4.40-3.el6.x86_64.rpmLinux
Php54-php update (ELSA-2015-1219) php54-php-5.4.40-3.el7.x86_64.rpmLinux
Php54-php-bcmath update (ELSA-2015-1219) php54-php-bcmath-5.4.40-3.el7.x86_64.rpmLinux
Php54-php-cli update (ELSA-2015-1219) php54-php-cli-5.4.40-3.el7.x86_64.rpmLinux
Php54-php-common update (ELSA-2015-1219) php54-php-common-5.4.40-3.el7.x86_64.rpmLinux
Php54-php-dba update (ELSA-2015-1219) php54-php-dba-5.4.40-3.el7.x86_64.rpmLinux
Php54-php-devel update (ELSA-2015-1219) php54-php-devel-5.4.40-3.el7.x86_64.rpmLinux
Php54-php-enchant update (ELSA-2015-1219) php54-php-enchant-5.4.40-3.el7.x86_64.rpmLinux
Php54-php-fpm update (ELSA-2015-1219) php54-php-fpm-5.4.40-3.el7.x86_64.rpmLinux
Php54-php-gd update (ELSA-2015-1219) php54-php-gd-5.4.40-3.el7.x86_64.rpmLinux
Php54-php-intl update (ELSA-2015-1219) php54-php-intl-5.4.40-3.el7.x86_64.rpmLinux
Php54-php-ldap update (ELSA-2015-1219) php54-php-ldap-5.4.40-3.el7.x86_64.rpmLinux
Php54-php-mbstring update (ELSA-2015-1219) php54-php-mbstring-5.4.40-3.el7.x86_64.rpmLinux
Php54-php-mysqlnd update (ELSA-2015-1219) php54-php-mysqlnd-5.4.40-3.el7.x86_64.rpmLinux
Php54-php-odbc update (ELSA-2015-1219) php54-php-odbc-5.4.40-3.el7.x86_64.rpmLinux
Php54-php-pdo update (ELSA-2015-1219) php54-php-pdo-5.4.40-3.el7.x86_64.rpmLinux
Php54-php-pgsql update (ELSA-2015-1219) php54-php-pgsql-5.4.40-3.el7.x86_64.rpmLinux
Php54-php-process update (ELSA-2015-1219) php54-php-process-5.4.40-3.el7.x86_64.rpmLinux
Php54-php-pspell update (ELSA-2015-1219) php54-php-pspell-5.4.40-3.el7.x86_64.rpmLinux
Php54-php-recode update (ELSA-2015-1219) php54-php-recode-5.4.40-3.el7.x86_64.rpmLinux
Php54-php-snmp update (ELSA-2015-1219) php54-php-snmp-5.4.40-3.el7.x86_64.rpmLinux
Php54-php-soap update (ELSA-2015-1219) php54-php-soap-5.4.40-3.el7.x86_64.rpmLinux
Php54-php-xml update (ELSA-2015-1219) php54-php-xml-5.4.40-3.el7.x86_64.rpmLinux
Php54-php-xmlrpc update (ELSA-2015-1219) php54-php-xmlrpc-5.4.40-3.el7.x86_64.rpmLinux
Update HP System Management Homepage Detection 7.5.3.1 to latest version (For Ubuntu)Linux
Update HP System Management Homepage Detection 7.5.3.1 to latest version (For Debian)Linux
Update HP System Management Homepage Detection 7.5.3.1 to latest version (For Centos)Linux
Update HP System Management Homepage Detection 7.5.3.1 to latest version (For RedHat)Linux
Update HP System Management Homepage Detection 7.5.3.1 to latest version (For Suse)Linux
Multiple Vulnerabilities affected in system_management_homepage 7.5.3.1NCM
Multiple Vulnerabilities affected in system_management_homepage 6.2.0NCM
Multiple Vulnerabilities affected in system_management_homepage 6.1.0.102NCM
Multiple Vulnerabilities affected in system_management_homepage 6.1.0-103NCM
Multiple Vulnerabilities affected in system_management_homepage 6.0.0.96NCM
Multiple Vulnerabilities affected in system_management_homepage 6.0.0-95NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.12-200NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.12-118NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.11-197NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.11NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.10-186NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.9-178NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.8-177NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.7.168NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.6.156NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.5.146-bNCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.5.146NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.4.143NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.4-143NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.2.127NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.0.121NCM
Multiple Vulnerabilities affected in system_management_homepage 2.0.2.106NCM
Multiple Vulnerabilities affected in system_management_homepage 2.0.1.104NCM
Multiple Vulnerabilities affected in system_management_homepage 7.2.1NCM
Multiple Vulnerabilities affected in system_management_homepage 7.2NCM
Multiple Vulnerabilities affected in system_management_homepage 2.2.6NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.11.197-aNCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.10.186-cNCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.10.186-bNCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.10.186NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.10NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.8.179NCM
Multiple Vulnerabilities affected in system_management_homepage 7.1NCM
Multiple Vulnerabilities affected in system_management_homepage 7.0NCM
Multiple Vulnerabilities affected in system_management_homepage 6.3.1NCM
Multiple Vulnerabilities affected in system_management_homepage 6.3.0NCM
Multiple Vulnerabilities affected in system_management_homepage 2.2.8NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.15.210NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.15-210NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.15NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.14.20NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.14NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.12.201NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.0.64NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.0-68NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.0NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.2.77-bNCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.2.77NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.2-77NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.2NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.1.73NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.1-73NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.1NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.4NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.3.132NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.1NCM
Multiple Vulnerabilities affected in system_management_homepage 7.4.0NCM
Multiple Vulnerabilities affected in system_management_homepage 6.2.2.7NCM
Multiple Vulnerabilities affected in system_management_homepage 6.1NCM
Multiple Vulnerabilities affected in system_management_homepage 6.0NCM
Multiple Vulnerabilities affected in system_management_homepage 3.2.7NCM
Multiple Vulnerabilities affected in system_management_homepage 3.2.2NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.9NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.8NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.7-168NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.7NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.6-156NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.6NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.5-146NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.5NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.3NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.2-127NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.2NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.0-118NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.0-109NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.0-103(a)NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.0-103NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1NCM
Multiple Vulnerabilities affected in system_management_homepage 2.0.2NCM
Multiple Vulnerabilities affected in system_management_homepage 2.0.1NCM
Multiple Vulnerabilities affected in system_management_homepage 2.0.0NCM
CVE-2015-4024NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-600354OS X Yosemite 10.10.5 Update
PATCH-600458OS X Yosemite 10.10.5 Combo Update

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234