vendor:
PHP
by:
Not mentioned
7.5
CVSS
HIGH
Remote Denial-of-Service
Not mentioned
CWE
Product Name: PHP
Affected Version From: PHP versions prior to 5.3.6
Affected Version To: Not mentioned
Patch Exists: YES
Related CWE: Not mentioned
CPE: Not mentioned
Platforms Tested: Not mentioned
Not mentioned
Multiple Remote Denial-of-Service Vulnerabilities in PHP OpenSSL Extension
The 'OpenSSL' extension in PHP is prone to multiple remote denial-of-service vulnerabilities. Successful attacks will cause the application to consume excessive memory, creating a denial-of-service condition.
Mitigation:
Upgrade to PHP version 5.3.6 or later.