CVE-2018-15503

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
18/08/2018
Last modified:
08/11/2018

Description

The unpack implementation in Swoole version 4.0.4 lacks correct size checks in the deserialization process. An attacker can craft a serialized object to exploit this vulnerability and cause a SEGV.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:swoole:swoole:4.0.4:*:*:*:*:*:*:*