CVE-2023-0662

Updated: 2025-02-13 21:28:26.504505

Description:

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consumption and excessive number of log entries. This can cause denial of service on the affected server by exhausting CPU resources or disk space.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x HIGH 7.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU php 8.0.30 7.5 HIGH Not Vulnerable 2025-01-15 01:09:57
CentOS 6 ELS php 5.3.3 7.5 HIGH Released CLSA-2023:1678395661 2023-03-20 14:05:11
CentOS 7 ELS php 5.4.16 7.5 HIGH Released CLSA-2024:1706700142 2024-02-19 10:09:27
CentOS 8.4 ELS php 7.4.6 7.5 HIGH Released CLSA-2023:1679350071 2023-03-20 21:14:37
CentOS 8.5 ELS php 7.4.19 7.5 HIGH Released CLSA-2023:1679350425 2023-03-20 21:14:37
CloudLinux 6 ELS php 5.3.3 7.5 HIGH Released CLSA-2023:1678395833 2023-03-20 17:05:04
Oracle Linux 6 ELS php 5.3.3 7.5 HIGH Released CLSA-2023:1678396156 2023-03-09 20:03:07
Ubuntu 16.04 ELS php 7.0.33 7.5 HIGH Released CLSA-2023:1677784124 2023-03-02 16:04:17
Ubuntu 18.04 ELS php 7.2.24-0 7.5 HIGH Already Fixed 2023-06-29 17:06:54