mb_encode_mimeheader runs endlessly for some inputs

Inhalt

Summary

Certain inputs provided to mb_encode_mimeheader trigger an endless loop.

Details

A discernible pattern has not yet been identified, but a specific string consistently reproduces the issue.

PoC

In PHP 8.3.3, execute:

Verknuepfte CVEs

CVE-ID Severity (CVE.org) CVSS (CVE.org) EPSS EPSS-% Veroeffentlicht (CVE.org)

CVE-2024-2757

- - - -

Quellen-Details

Bezeichnung Name Kategorie Tags Zielgruppe Sprache Feed-URL
PHP Security (php/php-src GHSA)

php_sec

vendor_advisory php, runtime - de https://github.com/php/php-src/security/advisories