In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consumption and excessive number of log entries. This can cause denial of service on the affected server by exhausting CPU resources or disk space.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3345-1 | php7.3 security update |
Debian DSA |
DSA-5363-1 | php7.4 security update |
EUVD |
EUVD-2023-12695 | In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consumption and excessive number of log entries. This can cause denial of service on the affected server by exhausting CPU resources or disk space. |
Ubuntu USN |
USN-5902-1 | PHP vulnerabilities |
Ubuntu USN |
USN-5905-1 | PHP vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 18 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Feb 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consumption and excessive number of log entries. This can cause denial of service on the affected server by exhausting CPU resources or disk space. | In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consumption and excessive number of log entries. This can cause denial of service on the affected server by exhausting CPU resources or disk space. |
Status: PUBLISHED
Assigner: php
Published:
Updated: 2025-03-18T14:58:15.370Z
Reserved: 2023-02-03T18:37:37.552Z
Link: CVE-2023-0662
Updated: 2024-08-02T05:17:50.335Z
Status : Modified
Published: 2023-02-16T07:15:10.577
Modified: 2025-02-13T17:15:56.090
Link: CVE-2023-0662
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN