Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3710

Опубликовано: 22 окт. 2014
Источник: redhat
CVSS2: 4.3

Описание

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

An out-of-bounds read flaw was found in the way the File Information (fileinfo) extension parsed Executable and Linkable Format (ELF) files. A remote attacker could use this flaw to crash a PHP application using fileinfo via a specially crafted ELF file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5fileWill not fix
Red Hat Enterprise Linux 5phpNot affected
Red Hat Enterprise Linux 5php53FixedRHSA-2014:176830.10.2014
Red Hat Enterprise Linux 6phpFixedRHSA-2014:176730.10.2014
Red Hat Enterprise Linux 6fileFixedRHSA-2016:076010.05.2016
Red Hat Enterprise Linux 7phpFixedRHSA-2014:176730.10.2014
Red Hat Enterprise Linux 7fileFixedRHSA-2015:215519.11.2015
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6php54-phpFixedRHSA-2014:176530.10.2014
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6php55-phpFixedRHSA-2014:176630.10.2014
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUSphp54-phpFixedRHSA-2014:176530.10.2014

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1155071file: out-of-bounds read in elf note headers

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

nvd
больше 10 лет назад

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

debian
больше 10 лет назад

The donote function in readelf.c in file through 5.20, as used in the ...

github
около 3 лет назад

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

oracle-oval
больше 10 лет назад

ELSA-2014-1768: php53 security update (IMPORTANT)

4.3 Medium

CVSS2