Vulnerability record · CVE-2004-0594 · published 27 July 2004
CVE-2004-0594: PHP memory_limit abort race allows remote code execution
Openpkg · Openpkg
PHP 4.x up to 4.3.7 and 5.x up to 5.0.0RC3 mishandle the memory_limit abort path, allowing a HashTable destructor pointer to be overwritten before key data structures are initialized. When conditions such as register_globals being enabled are met, this race condition lets remote attackers execute arbitrary code. It matters because it turns a resource-limit failure into a code execution primitive on affected PHP deployments.
Description
The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute arbitrary code by triggering a memory_limit abort during execution of the zend_hash_init function and overwriting a HashTable destructor pointer before the initialization of key data structures is complete.
AV:N/AC:H/Au:N/C:P/I:P/A:P
Automated analysis
high priorityAlthough the CVSS v2 score is medium and access complexity is high, the flaw allows remote code execution and EPSS predicts a high likelihood of exploitation.
What it is
PHP 4.x up to 4.3.7 and 5.x up to 5.0.0RC3 mishandle the memory_limit abort path, allowing a HashTable destructor pointer to be overwritten before key data structures are initialized. When conditions such as register_globals being enabled are met, this race condition lets remote attackers execute arbitrary code. It matters because it turns a resource-limit failure into a code execution primitive on affected PHP deployments.
Impact
An attacker can execute arbitrary code in the context of the PHP process, potentially taking over the web server or application. This can lead to full compromise of the host or data served by it.
Attack surface
The vulnerability is network-reachable (AV:N) and requires no authentication (Au:N), but the CVSS vector rates access complexity as high (AC:H), reflecting the specific conditions and timing needed. No user interaction is indicated.
Exploitation
CVE-2004-0594 is not listed in CISA KEV, but EPSS shows a 30-day probability of 0.54856 (98.975th percentile), indicating high predicted exploitation activity. Reference tags are advisory and VDB entries only, with no public exploit tag supplied.
What to do
- Upgrade PHP to a version later than 4.3.7 or 5.0.0RC3 that contains the fix.
- Disable register_globals where possible, since the description identifies it as a condition that enables the flaw.
- Apply vendor security updates for PHP packages on Debian, Red Hat, Gentoo, Mandrake, Novell/SUSE, Trustix, HP-UX, Avaya, and OpenPKG systems.
- Restrict network access to PHP application endpoints to trusted clients where feasible.
- Monitor and tune memory_limit settings to avoid triggering the abort path under attacker-controlled conditions.
Detection
- Monitor PHP error logs for memory_limit abort messages followed by abnormal process behavior or crashes.
- Look for unexpected child process creation or outbound connections from the web/PHP server process.
- Audit PHP configurations for register_globals being enabled on affected versions.
- Use host-based intrusion detection to flag code execution or memory corruption indicators in PHP processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0594 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0594), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.