CVE-2009-4017
24.11.2009, 00:30
PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, which allows remote attackers to cause a denial of service (resource exhaustion), and makes it easier for remote attackers to exploit local file inclusion vulnerabilities, via multiple requests, related to lack of support for the max_file_uploads directive.Enginsight
Vendor | Product | Version |
---|---|---|
php | php | 𝑥 < 5.2.12 |
php | php | 5.3.0 |
php | php | 5.3.0:alpha1 |
php | php | 5.3.0:alpha2 |
php | php | 5.3.0:alpha3 |
php | php | 5.3.0:beta1 |
php | php | 5.3.0:rc1 |
php | php | 5.3.0:rc2 |
php | php | 5.3.0:rc3 |
php | php | 5.3.0:rc4 |
apple | mac_os_x | 10.6.3 |
debian | debian_linux | 4.0 |
debian | debian_linux | 5.0 |
debian | debian_linux | 6.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References