CVE-2005-0524: Medium severity PHP PHP vulnerability
Published Apr 3, 2005
·Updated
The phphandleiff function in image.c for PHP 4.2.2, 4.3.9, 4.3.10 and 5.0.3, as reachable by the getimagesize PHP function, allows remote attackers to cause a denial of service (infinite loop) via a -8 size value.
Affected Software
4 affected components
PHP PHP=4.3.9
PHP PHP=4.2.2
PHP PHP=5.0.3
PHP PHP=4.3.10
Remediation
Patch Available
Patch Available
Patch Available
Event History
Apr 3, 2005
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0524?
CVE-2005-0524 has a severity rating that indicates it can cause a denial of service by leading to an infinite loop.
2
How do I fix CVE-2005-0524?
To fix CVE-2005-0524, you should upgrade your PHP version to one that is not affected, such as a version higher than 5.0.3.
3
Which versions of PHP are affected by CVE-2005-0524?
CVE-2005-0524 affects PHP versions 4.2.2, 4.3.9, 4.3.10, and 5.0.3.
4
Can CVE-2005-0524 be exploited remotely?
Yes, CVE-2005-0524 can be exploited remotely by attackers through the getimagesize PHP function.
5
What are the symptoms of CVE-2005-0524 exploitation?
Exploitation of CVE-2005-0524 typically results in a denial of service, which can manifest as unresponsive applications or servers.