PHP Allocation of Resources Without Limits or Throttling Vulnerability - CVE-2017-7963 - Vulnerability Database

PHP Allocation of Resources Without Limits or Throttling Vulnerability - CVE-2017-7963

High
Reference: CVE-2017-7963
Title: PHP Allocation of Resources Without Limits or Throttling Vulnerability
Overview:

DISPUTED The GNU Multiple Precision Arithmetic Library (GMP) interfaces for PHP through 7.1.4 allow attackers to cause a denial of service (memory consumption and application crash) via operations on long strings. NOTE: the vendor disputes this stating quotThere is no security issue here because GMP safely aborts in case of an OOM condition. The only attack vector here is denial of service. However if you allow attacker-controlled unbounded allocations you have a DoS vector regardless of GMP39s OOM behavior.quot