4.3

CVE-2014-0207

The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted CDF file.

Data is provided by the National Vulnerability Database (NVD)
Christos ZoulasFile Version < 5.19
PhpPhp Version < 5.3.29
PhpPhp Version >= 5.4.0 < 5.4.30
PhpPhp Version >= 5.5.0 < 5.5.14
OracleLinux Version7 Update-
OpensuseOpensuse Version11.4
DebianDebian Linux Version7.0
DebianDebian Linux Version8.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 8.85% 0.922
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://www.php.net/ChangeLog-5.php
Vendor Advisory
Release Notes
http://marc.info/?l=bugtraq&m=141017844705317&w=2
Third Party Advisory
Mailing List
Issue Tracking
http://www.securityfocus.com/bid/68243
Third Party Advisory
VDB Entry
https://bugs.php.net/bug.php?id=67326
Patch
Vendor Advisory
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=1091842
Patch
Third Party Advisory
Issue Tracking