Denial of Service (DoS) Affecting php package, versions [4.3.0,4.3.2]


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
5.93% (94th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Denial of Service (DoS) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-UNMANAGED-PHP-2335121
  • published12 Jan 2022
  • disclosed17 Nov 2003
  • creditUnknown

Introduced: 17 Nov 2003

CVE-2003-0863  (opens in a new tab)
CWE-400  (opens in a new tab)

How to fix?

There is no fixed version for php.

Overview

Affected versions of this package are vulnerable to Denial of Service (DoS). The php_check_safe_mode_include_dir function in fopen_wrappers.c of PHP 4.3.x returns a success value (0) when the safe_mode_include_dir variable is not specified in configuration, which differs from the previous failure value and may allow remote attackers to exploit file include vulnerabilities in PHP applications.

CVSS Scores

version 3.1