CVE-2011-1471

PHP <5.3.6 - DoS

Title source: llm

Description

Integer signedness error in zip_stream.c in the Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (CPU consumption) via a malformed archive file that triggers errors in zip_fread function calls.

Exploits (1)

exploitdb WORKING POC VERIFIED
by TorokAlpar · phpdosphp
https://www.exploit-db.com/exploits/35485

Scores

EPSS 0.0723
EPSS Percentile 91.6%

Details

CWE
CWE-189
Status published
Products (1)
php/php < 5.2.11
Published Mar 20, 2011
Tracked Since Feb 18, 2026