CVE-2009-4017 is a resource-management vulnerability in PHP affecting versions before 5.2.12 and 5.3.x before 5.3.1. When processing multipart/form-data POST requests, PHP did not enforce a limit on the number of temporary files created for uploaded parts because support for the max_file_uploads directive was lacking. An attacker could submit requests containing a large number of MIME parts, or send multiple such requests, causing PHP to create excessive temporary files during upload handling. This represents an allocation-of-resources-without-limits condition in the upload-processing path and can exhaust available system resources. In addition to denial-of-service risk, the uncontrolled creation of temporary upload files can make exploitation of local file inclusion vulnerabilities easier under some conditions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A denial-of-service vulnerability in PHP's handling of multipart/form-data POST requests that allows uncontrolled temporary file creation, leading to resource exhaustion and potentially facilitating exploitation of local file inclusion vulnerabilities.
A vulnerability in a language interpreter involving unrestricted temporary file creation during MIME handling, mentioned only as an example under CWE-770.
A CVE cited as an observed example where a language interpreter allows resource exhaustion by creating too many temporary files while handling MIME requests.
A denial-of-service vulnerability where a language interpreter can be forced to create an excessive number of temporary files when processing a MIME request with many parts, exhausting resources.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.