4.3

CVE-2014-3479

The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to cause a denial of service (application crash) via a crafted stream offset in a CDF file.

Data is provided by the National Vulnerability Database (NVD)
File ProjectFile Version < 5.19
PhpPhp Version < 5.3.29
PhpPhp Version >= 5.4.0 < 5.4.30
PhpPhp Version >= 5.5.0 < 5.5.14
DebianDebian Linux Version7.0
DebianDebian Linux Version8.0
OpensuseOpensuse Version11.4
OracleLinux Version7 Update-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 11.28% 0.933
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
http://www.php.net/ChangeLog-5.php
Vendor Advisory
Release Notes
http://marc.info/?l=bugtraq&m=141017844705317&w=2
Third Party Advisory
Issue Tracking
http://www.securityfocus.com/bid/68241
Third Party Advisory
VDB Entry
https://bugs.php.net/bug.php?id=67411
Patch
Vendor Advisory
Issue Tracking