CVE-2009-4418
Publication date 24 December 2009
Last updated 24 July 2024
Ubuntu priority
Description
The unserialize function in PHP 5.3.0 and earlier allows context-dependent attackers to cause a denial of service (resource consumption) via a deeply nested serialized variable, as demonstrated by a string beginning with a:1: followed by many {a:1: sequences.
Notes
mdeslaur
as of 2010/01/04, not fixed yet can only be exploited by a malicious script, not a security issue. Marking as ignored.