Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-9652

Опубликовано: 30 мар. 2015
Источник: debian
EPSS Низкий

Описание

The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
filefixed1:5.21+15-1package
filenot-affectedsqueezepackage
filefixed5.11-2+deb7u7wheezypackage
php5fixed5.6.5+dfsg-1package
php5fixed5.4.36-0+deb7u3wheezypackage

Примечания

  • http://bugs.gw.com/view.php?id=398

  • https://github.com/file/file/commit/59e63838913eee47f5c120a6c53d4565af638158

  • https://bugs.php.net/bug.php?id=68735

EPSS

Процентиль: 88%
0.04342
Низкий

Связанные уязвимости

ubuntu
больше 10 лет назад

The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file.

redhat
больше 10 лет назад

The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file.

nvd
больше 10 лет назад

The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file.

github
около 3 лет назад

The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file.

fstec
больше 11 лет назад

Уязвимость интерпретатора PHP, позволяющая удалённому злоумышленнику получить доступ к области памяти за пределами границ приложения или вызвать аварийное завершение приложения

EPSS

Процентиль: 88%
0.04342
Низкий