Permissions, Privileges, and Access Controls in PHP - CVE-2013-7345
Published: March 24, 2014 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses multiple wildcards with unlimited repetitions, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted ASCII file that triggers a large amount of backtracking, as demonstrated via a file with many newline characters.
Affected software
Gentoo Linux
Amazon Linux AMI
Slackware Linux
php (Alpine package)
dev-lang/php
How to mitigate CVE-2013-7345
dev-lang/php - update to 5.5.16
External References
Related Security Bulletins
- Permissions, Privileges, and Access Controls in PHP
- Permissions, Privileges, and Access Controls in php (Alpine package)
- Amazon Linux AMI update for file
- Amazon Linux AMI update for php54
- Amazon Linux AMI update for php55
- Amazon Linux AMI update for php54
- Amazon Linux AMI update for php55
- Amazon Linux AMI update for file
- Gentoo update for file
- Slackware Linux update for php
- Gentoo update for PHP