RULE(RULE ID:312094)

Rule General Information
Release Date: 2016-01-05
Rule Name: PHP HTTP Multipart Form-data Denial of Service Vulnerability (CVE-2015-4024)
Severity:
CVE ID:
Rule Protection Details
Description: Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU consumption) via crafted form data that triggers an improper order-of-growth outcome.
Impact: An attacker can launch a denial of service attack by exploiting the vulnerability successfully.
Affected OS: Windows
Reference: SecurityFocusBID:74903
SecurityTrackerID:1032432
Solutions
More advisories have been published on the website, please visit for more suggestions:
https://bugs.php.net/bug.php?id=69364