Release date: 2011-12-29
Updated on: 2011-12-31
Affected Systems:
PHP 5.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51193
Cve id: CVE-2011-4885
PHP is an English Super Text preprocessing language.
In versions earlier than PHP 5.3.9, hash conflicts are not limited in advance in the implementation of form parameter hash values. A denial of service vulnerability exists and a small amount of specially crafted webform form is sent to the affected application, attackers can exploit this vulnerability to cause PHP websites to lose the ability to respond to normal requests.
<* Source: Alexander Klink (a.klink@cynops.de)
Link: http://www.ocert.org/advisories/ocert-2011-003.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PHP
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.php.net