CVE-2018-10546
HIGHPHP <5.6.36, <7.0.30, <7.1.17, <7.2.5 - Info Disclosure
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-10546. PoCs published by dsfau.
AI-analyzed exploit summary This PoC demonstrates CVE-2018-10546, a CPU exhaustion vulnerability in PHP's stream filter 'convert.iconv.*' that causes an infinite loop when processing crafted data. The exploit uses a memory stream with a malformed filter chain to trigger the DoS condition.
Description
An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. An infinite loop exists in ext/iconv/iconv.c because the iconv stream filter does not reject invalid multibyte sequences.
Exploits (1)
This PoC demonstrates CVE-2018-10546, a CPU exhaustion vulnerability in PHP's stream filter 'convert.iconv.*' that causes an infinite loop when processing crafted data. The exploit uses a memory stream with a malformed filter chain to trigger the DoS condition.
References (12)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H