Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8626

Опубликовано: 05 нояб. 2014
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

Stack-based buffer overflow in the date_from_ISO8601 function in ext/xmlrpc/libxmlrpc/xmlrpc.c in PHP before 5.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by including a timezone field in a date, leading to improper XML-RPC encoding.

A stack-based buffer overflow flaw was found in the way the xmlrpc extension parsed dates in the ISO 8601 format. A specially crafted XML-RPC request or response could possibly cause a PHP application to crash or execute arbitrary code with the privileges of the user running that PHP application.

Отчет

This issue did not affect php53 packages in Red Hat Enterprise Linux 5, php packages in Red Hat Enterprise Linux 6 and 7, and php54-php and php55-php packages in Red Hat Software Collections 1.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5php53Not affected
Red Hat Enterprise Linux 6phpNot affected
Red Hat Enterprise Linux 7phpNot affected
Red Hat Software Collectionsphp54-phpNot affected
Red Hat Software Collectionsphp55-phpNot affected
Red Hat Enterprise Linux 4 Extended Lifecycle SupportphpFixedRHSA-2014:182506.11.2014
Red Hat Enterprise Linux 5phpFixedRHSA-2014:182406.11.2014

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=1155607php: xmlrpc ISO8601 date format parsing buffer overflow

EPSS

Процентиль: 88%
0.04168
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

Stack-based buffer overflow in the date_from_ISO8601 function in ext/xmlrpc/libxmlrpc/xmlrpc.c in PHP before 5.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by including a timezone field in a date, leading to improper XML-RPC encoding.

nvd
больше 10 лет назад

Stack-based buffer overflow in the date_from_ISO8601 function in ext/xmlrpc/libxmlrpc/xmlrpc.c in PHP before 5.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by including a timezone field in a date, leading to improper XML-RPC encoding.

debian
больше 10 лет назад

Stack-based buffer overflow in the date_from_ISO8601 function in ext/x ...

github
около 3 лет назад

Stack-based buffer overflow in the date_from_ISO8601 function in ext/xmlrpc/libxmlrpc/xmlrpc.c in PHP before 5.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by including a timezone field in a date, leading to improper XML-RPC encoding.

oracle-oval
больше 10 лет назад

ELSA-2014-1824: php security update (IMPORTANT)

EPSS

Процентиль: 88%
0.04168
Низкий

6.8 Medium

CVSS2