Vulnerabilities > CVE-2018-15503 - Deserialization of Untrusted Data vulnerability in Swoole 4.0.4

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
swoole
CWE-502

Summary

The unpack implementation in Swoole version 4.0.4 lacks correct size checks in the deserialization process. An attacker can craft a serialized object to exploit this vulnerability and cause a SEGV.

Vulnerable Configurations

Part Description Count
Application
Swoole
1

Common Weakness Enumeration (CWE)