suse · CVE-2011-4885

Quick triage

Priority: medium Published: 2021-05-30 13:00:57 UTC Updated: 2026-04-18 19:55:25 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2011-4885 severity moderate: SUSE including 426 source package names (apache2-mod_php5-5.2.14-0.7.30.34.1, apache2-mod_php5-5.6.28-1.1, …), 426 product×package rows across 14 product lines (SUSE Linux Enterprise Server 11 SP1-TERADATA, SUSE Linux Enterprise Server 11 SP2, … (14 product lines)): Fixed 426.

Description:

PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

cvelogic Threat Intelligence