CVE-2023-0662

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consumption and excessive number of log entries. This can cause denial of service on the affected server by exhausting CPU resources or disk space. 
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*

History

17 May 2023, 20:15

Type Values Removed Values Added
Summary In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consumption and excessive number of log entries. This can cause denial of service on the affected server by exhausting CPU resources or disk space. In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consumption and excessive number of log entries. This can cause denial of service on the affected server by exhausting CPU resources or disk space. 
References
  • (MISC) https://security.netapp.com/advisory/ntap-20230517-0001/ -

24 Feb 2023, 18:09

Type Values Removed Values Added
References (MISC) https://github.com/php/php-src/security/advisories/GHSA-54hq-v5wp-fqgv - (MISC) https://github.com/php/php-src/security/advisories/GHSA-54hq-v5wp-fqgv - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-400
CPE cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
First Time Php
Php php

16 Feb 2023, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-02-16 07:15

Updated : 2023-12-10 14:48


NVD link : CVE-2023-0662

Mitre link : CVE-2023-0662

CVE.ORG link : CVE-2023-0662


JSON object : View

Products Affected

php

  • php
CWE
CWE-400

Uncontrolled Resource Consumption