PHP is prone to a denial-of-service vulnerability.
An attacker may exploit this issue to crash the affected application, resulting in a denial-of-service condition.
PHP 7.1.5 is vulnerable; other versions may also be affected.
Information
Exploit
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
References:
- Fixed bug #74600 (PHP)
- PHP 7 ChangeLog (PHP)
- PHP Homepage (PHP)
- Bug #74600 crash (SIGSEGV) in _zend_hash_add_or_update_i (PHP)