Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-9426

Опубликовано: 31 дек. 2014
Источник: nvd
CVSS3: 7.3
CVSS2: 7.5
EPSS Низкий

Описание

The apprentice_load function in libmagic/apprentice.c in the Fileinfo component in PHP through 5.6.4 attempts to perform a free operation on a stack-based character array, which allows remote attackers to cause a denial of service (memory corruption or application crash) or possibly have unspecified other impact via unknown vectors. NOTE: this is disputed by the vendor because the standard erealloc behavior makes the free operation unreachable

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
Версия до 5.6.4 (включая)

EPSS

Процентиль: 73%
0.00785
Низкий

7.3 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-17

Связанные уязвимости

CVSS3: 7.3
ubuntu
больше 10 лет назад

** DISPUTED ** The apprentice_load function in libmagic/apprentice.c in the Fileinfo component in PHP through 5.6.4 attempts to perform a free operation on a stack-based character array, which allows remote attackers to cause a denial of service (memory corruption or application crash) or possibly have unspecified other impact via unknown vectors. NOTE: this is disputed by the vendor because the standard erealloc behavior makes the free operation unreachable.

redhat
больше 10 лет назад

The apprentice_load function in libmagic/apprentice.c in the Fileinfo component in PHP through 5.6.4 attempts to perform a free operation on a stack-based character array, which allows remote attackers to cause a denial of service (memory corruption or application crash) or possibly have unspecified other impact via unknown vectors. NOTE: this is disputed by the vendor because the standard erealloc behavior makes the free operation unreachable

CVSS3: 7.3
debian
больше 10 лет назад

The apprentice_load function in libmagic/apprentice.c in the Fileinfo ...

CVSS3: 7.3
github
около 3 лет назад

** DISPUTED ** The apprentice_load function in libmagic/apprentice.c in the Fileinfo component in PHP through 5.6.4 attempts to perform a free operation on a stack-based character array, which allows remote attackers to cause a denial of service (memory corruption or application crash) or possibly have unspecified other impact via unknown vectors. NOTE: this is disputed by the vendor because the standard erealloc behavior makes the free operation unreachable.

CVSS3: 7.3
fstec
больше 10 лет назад

Уязвимость функции apprentice_load интерпретатора языка программирования PHP, позволяющая нарушителю вызвать отказ в обслуживании или, возможно, оказать другое воздействие

EPSS

Процентиль: 73%
0.00785
Низкий

7.3 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-17