CVE-2015-9253

EUVD-2015-9096
An issue was discovered in PHP 7.3.x before 7.3.0alpha3, 7.2.x before 7.2.8, and before 7.1.20. The php-fpm master process restarts a child process in an endless loop when using program execution functions (e.g., passthru, exec, shell_exec, or system) with a non-blocking STDIN stream, causing this master process to consume 100% of the CPU, and consume disk space with a large volume of error logs, as demonstrated by an attack by a customer of a shared-hosting facility.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
Affected Products (NVD)
VendorProductVersion
phpphp
𝑥
< 7.1.20
phpphp
7.2.0 ≤
𝑥
< 7.2.8
phpphp
7.3.0:alpha1
phpphp
7.3.0:alpha2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
php5
artful
dne
bionic
dne
cosmic
dne
disco
dne
eoan
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
trusty
Fixed 5.5.9+dfsg-1ubuntu4.29+esm10
released
xenial
dne
php7.0
artful
dne
bionic
dne
cosmic
dne
disco
dne
eoan
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
trusty
dne
xenial
Fixed 7.0.33-0ubuntu0.16.04.16+esm3
released
php7.2
artful
dne
bionic
Fixed 7.2.10-0ubuntu0.18.04.1
released
cosmic
Fixed 7.2.10-0ubuntu1
released
disco
Fixed 7.2.10-0ubuntu1
released
eoan
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
trusty
dne
xenial
dne
php7.3
bionic
dne
eoan
not-affected
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
trusty
dne
xenial
dne