CVE-2009-4017

PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, which allows remote attackers to cause a denial of service (resource exhaustion), and makes it easier for remote attackers to exploit local file inclusion vulnerabilities, via multiple requests, related to lack of support for the max_file_uploads directive.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
VendorProductVersion
phpphp
𝑥
< 5.2.12
phpphp
5.3.0
phpphp
5.3.0:alpha1
phpphp
5.3.0:alpha2
phpphp
5.3.0:alpha3
phpphp
5.3.0:beta1
phpphp
5.3.0:rc1
phpphp
5.3.0:rc2
phpphp
5.3.0:rc3
phpphp
5.3.0:rc4
applemac_os_x
10.6.3
debiandebian_linux
4.0
debiandebian_linux
5.0
debiandebian_linux
6.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
php5
karmic
Fixed 5.2.10.dfsg.1-2ubuntu6.3
released
jaunty
Fixed 5.2.6.dfsg.1-3ubuntu4.4
released
intrepid
Fixed 5.2.6-2ubuntu4.5
released
hardy
Fixed 5.2.4-2ubuntu5.9
released
dapper
Fixed 5.1.2-1ubuntu3.17
released
References