Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3rf4-9569-4jw7

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

Ссылки

EPSS

Процентиль: 93%
0.09697
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 10 лет назад

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

redhat
больше 10 лет назад

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

nvd
больше 10 лет назад

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

debian
больше 10 лет назад

The donote function in readelf.c in file through 5.20, as used in the ...

oracle-oval
больше 10 лет назад

ELSA-2014-1768: php53 security update (IMPORTANT)

EPSS

Процентиль: 93%
0.09697
Низкий

Дефекты

CWE-20