First published: Fri Feb 17 2023(Updated: )
In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consumption and excessive number of log entries. This can cause denial of service on the affected server by exhausting CPU resources or disk space. <a href="https://github.com/php/php-src/security/advisories/GHSA-54hq-v5wp-fqgv">https://github.com/php/php-src/security/advisories/GHSA-54hq-v5wp-fqgv</a>
Affected Software | Affected Version | How to fix |
---|---|---|
PHP | <8.0.28 | |
PHP | <8.1.16 | |
PHP | <8.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2170761 is high due to potential denial of service caused by excessive resource consumption.
To fix REDHAT-BUG-2170761, upgrade your PHP versions to 8.0.28, 8.1.16, or 8.2.3 or later.
PHP versions 8.0.X before 8.0.28, 8.1.X before 8.1.16, and 8.2.X before 8.2.3 are affected by REDHAT-BUG-2170761.
The issue in REDHAT-BUG-2170761 is caused by an excessive number of parts in HTTP form uploads, leading to resource exhaustion.
Yes, REDHAT-BUG-2170761 can lead to server downtime due to denial of service from CPU or disk space exhaustion.