#VU32548 Permissions, Privileges, and Access Controls in PHP - CVE-2013-7345
Published: March 24, 2014 / Updated: July 28, 2020
PHP
PHP Group
Description
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses multiple wildcards with unlimited repetitions, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted ASCII file that triggers a large amount of backtracking, as demonstrated via a file with many newline characters.