CVE-2015-4024: Medium severity red hat enterprise linux vulnerability
Algorithmic complexity vulnerability in the multipartbufferheaders function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU consumption) via crafted form data that triggers an improper order-of-growth outcome.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4024?
CVE-2015-4024 is classified as a denial of service vulnerability that can lead to significant CPU consumption.
How do I fix CVE-2015-4024?
To mitigate CVE-2015-4024, upgrade your PHP version to at least 5.4.41, 5.5.25, or 5.6.9.
What versions of PHP are affected by CVE-2015-4024?
CVE-2015-4024 affects PHP versions prior to 5.4.41, all 5.5.x versions before 5.5.25, and all 5.6.x versions before 5.6.9.
Can CVE-2015-4024 be exploited remotely?
Yes, CVE-2015-4024 can be exploited by remote attackers using crafted form data.
What impact does CVE-2015-4024 have on systems?
The impact of CVE-2015-4024 includes increased CPU usage that could lead to service outages.