The array_fill function in ext/standard/array.c in PHP 4.4.2 and 5.1.2 allows context-dependent attackers to cause a denial of service (memory consumption) via a large num value.
Link | Tags |
---|---|
http://securitytracker.com/id?1015979 | vdb entry exploit |
http://www.infigo.hr/hr/in_focus/advisories/INFIGO-2006-04-02 | exploit vendor advisory |
http://www.osvdb.org/24945 | vdb entry |