CVE-2015-9253

An issue was discovered in PHP 7.3.x before 7.3.0alpha3, 7.2.x before 7.2.8, and before 7.1.20. The php-fpm master process restarts a child process in an endless loop when using program execution functions (e.g., passthru, exec, shell_exec, or system) with a non-blocking STDIN stream, causing this master process to consume 100% of the CPU, and consume disk space with a large volume of error logs, as demonstrated by an attack by a customer of a shared-hosting facility.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
VendorProductVersion
phpphp
𝑥
< 7.1.20
phpphp
7.2.0 ≤
𝑥
< 7.2.8
phpphp
7.3.0:alpha1
phpphp
7.3.0:alpha2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
php5
jammy
dne
impish
dne
hirsute
dne
groovy
dne
focal
dne
eoan
dne
disco
dne
cosmic
dne
bionic
dne
artful
dne
xenial
dne
trusty
Fixed 5.5.9+dfsg-1ubuntu4.29+esm10
released
php7.0
jammy
dne
impish
dne
hirsute
dne
groovy
dne
focal
dne
eoan
dne
disco
dne
cosmic
dne
bionic
dne
artful
dne
xenial
Fixed 7.0.33-0ubuntu0.16.04.16+esm3
released
trusty
dne
php7.2
jammy
dne
impish
dne
hirsute
dne
groovy
dne
focal
dne
eoan
dne
disco
Fixed 7.2.10-0ubuntu1
released
cosmic
Fixed 7.2.10-0ubuntu1
released
bionic
Fixed 7.2.10-0ubuntu0.18.04.1
released
artful
dne
xenial
dne
trusty
dne
php7.3
jammy
dne
impish
dne
hirsute
dne
groovy
dne
focal
dne
eoan
not-affected
bionic
dne
xenial
dne
trusty
dne