CVE-2024-2757

In PHP 8.3.* before 8.3.5, function mb_encode_mimeheader() runs endlessly for some inputs that contain long strings of non-space characters followed by a space. This could lead to a potential DoS attack if a hostile user sends data to an application that uses this function. 
Configurations

No configuration.

History

21 Nov 2024, 09:10

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2024/04/12/11 - () http://www.openwall.com/lists/oss-security/2024/04/12/11 -
References () https://github.com/php/php-src/security/advisories/GHSA-fjp9-9hwx-59fq - () https://github.com/php/php-src/security/advisories/GHSA-fjp9-9hwx-59fq -
References () https://security.netapp.com/advisory/ntap-20240510-0011/ - () https://security.netapp.com/advisory/ntap-20240510-0011/ -

03 Jul 2024, 01:53

Type Values Removed Values Added
CWE CWE-400

10 Jun 2024, 17:16

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20240510-0011/ -

01 May 2024, 17:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/04/12/11 -
Summary
  • (es) En PHP 8.3.* anterior a 8.3.5, la función mb_encode_mimeheader() se ejecuta sin cesar para algunas entradas que contienen cadenas largas de caracteres que no son espacios seguidos de un espacio. Esto podría provocar un posible ataque DoS si un usuario hostil envía datos a una aplicación que utiliza esta función.

29 Apr 2024, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-29 04:15

Updated : 2024-11-21 09:10


NVD link : CVE-2024-2757

Mitre link : CVE-2024-2757

CVE.ORG link : CVE-2024-2757


JSON object : View

Products Affected

No product.

CWE
CWE-400

Uncontrolled Resource Consumption