Doc #61883 [Opn->Csd]: Missing info
| From: | kobrasrealm at gmail dot com | Date: | Tue, 01 May 2012 00:07:01 +0000 |
| Subject: | Doc #61883 [Opn->Csd]: Missing info | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-8316@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=61883&edit=1
ID: 61883
User updated by: kobrasrealm at gmail dot com
Reported by: kobrasrealm at gmail dot com
Summary: Missing info
-Status: Open
+Status: Closed
Type: Documentation Problem
Package: Website problem
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
fsfsf
Previous Comments:
------------------------------------------------------------------------
[2012-05-01 00:06:33] kobrasrealm at gmail dot com
Dammit. Form complete erased the title.
------------------------------------------------------------------------
[2012-05-01 00:06:07] kobrasrealm at gmail dot com
Description:
------------
From http://1337day.com/exploits/18161 >>
PHP 5.4.1 getimagesize() Denial of Service Memory leak
Details:
Getimagesize function is used to determine the size of an image. It recives
one parameter as URI. Getimagesize() doesn't implement any function to
verify if the remote file that is been downloaded is an image nor if the
size is higher than desired, so it could be possible to force the PHP
engine to download (through Getimagesize()) a huge file, causing a DoS (in
RAM and CPU) in the webserver.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=61883&edit=1