Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-9620

Опубликовано: 03 янв. 2015
Источник: redhat
CVSS2: 1.9
EPSS Низкий

Описание

The ELF parser in file 5.08 through 5.21 allows remote attackers to cause a denial of service via a large number of notes.

A flaw was found in the way the File Information (fileinfo) extension parsed Executable and Linkable Format (ELF) files. A remote attacker could use this flaw to crash a PHP application using fileinfo via a specially crafted ELF file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5cdrtoolsNot affected
Red Hat Enterprise Linux 5fileWill not fix
Red Hat Enterprise Linux 5php53Not affected
Red Hat Enterprise Linux 5rpmWill not fix
Red Hat Enterprise Linux 6phpNot affected
Red Hat Enterprise Linux 7fileWill not fix
Red Hat Enterprise Linux 7phpNot affected
Red Hat Software Collectionsphp54-phpNot affected
Red Hat Software Collectionsphp55-phpNot affected
Red Hat Software Collectionsrh-php56-phpNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=1180639file: limit the number of ELF notes processed

EPSS

Процентиль: 86%
0.03175
Низкий

1.9 Low

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

The ELF parser in file 5.08 through 5.21 allows remote attackers to cause a denial of service via a large number of notes.

nvd
больше 10 лет назад

The ELF parser in file 5.08 through 5.21 allows remote attackers to cause a denial of service via a large number of notes.

debian
больше 10 лет назад

The ELF parser in file 5.08 through 5.21 allows remote attackers to ca ...

github
около 3 лет назад

The ELF parser in file 5.08 through 5.21 allows remote attackers to cause a denial of service via a large number of notes.

suse-cvrf
больше 7 лет назад

Security update for file

EPSS

Процентиль: 86%
0.03175
Низкий

1.9 Low

CVSS2