cbcvebase.
CVE-2015-4024
published 2015-06-09

CVE-2015-4024: Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before…

PriorityP338medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
50.13%
98.8th percentile
Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU consumption) via crafted form data that triggers an improper order-of-growth outcome.

Affected

47 ranges· showing 25
VendorProductVersion rangeFixed in
applemac_os_x<= 10.10.4
appleos_x_yosemite_v10.10.5_and_security_update_2015-006
hpsystem_management_homepage<= 7.5.3.1
oraclelinux
oraclelinux
oraclesolaris
phpphp<= 5.4.40
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp

Detection & IOCsextracted from sources · hover to see the quote

  • Target the multipart_buffer_headers function in main/rfc1867.c — a specially-crafted multipart/form-data HTTP POST request triggers algorithmic complexity (CPU exhaustion) in PHP's multipart parser.
  • Monitor for HTTP POST requests with Content-Type: multipart/form-data that are abnormally large or contain unusual header structures, which may indicate exploitation attempts targeting the PHP multipart parser.
  • Track upstream fix commit 4605d536d23b00813d11cc906bb48d39bdcf5f25 in php-src.git to confirm patched vs. unpatched PHP deployments.
  • ·The max_input_time php.ini setting (default 60s) limits the time spent parsing a malicious request and can be lowered as a mitigation; lowering post_max_size is an additional mitigation but may not be practical enough on its own.

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.