Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-3587

Опубликовано: 23 авг. 2014
Источник: ubuntu
Приоритет: low
EPSS Средний
CVSS2: 4.3

Описание

Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1571.

РелизСтатусПримечание
devel

released

1:5.19-1ubuntu1.1
esm-infra-legacy/trusty

not-affected

1:5.14-2ubuntu3.2
lucid

released

5.03-5ubuntu1.4
precise

released

5.09-2ubuntu0.5
trusty

released

1:5.14-2ubuntu3.2
trusty/esm

not-affected

1:5.14-2ubuntu3.2
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

released

5.5.12+dfsg-2ubuntu4
esm-infra-legacy/trusty

not-affected

5.5.9+dfsg-1ubuntu4.4
lucid

released

5.3.2-1ubuntu4.27
precise

released

5.3.10-1ubuntu3.14
trusty

released

5.5.9+dfsg-1ubuntu4.4
trusty/esm

not-affected

5.5.9+dfsg-1ubuntu4.4
upstream

needs-triage

Показывать по

EPSS

Процентиль: 95%
0.19104
Средний

4.3 Medium

CVSS2

Связанные уязвимости

redhat
почти 11 лет назад

Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1571.

nvd
почти 11 лет назад

Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1571.

debian
почти 11 лет назад

Integer overflow in the cdf_read_property_info function in cdf.c in fi ...

github
около 3 лет назад

Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1571.

fstec
почти 11 лет назад

Уязвимость программного обеспечения PHP, позволяющая удаленному злоумышленнику нарушить доступность защищаемой информации

EPSS

Процентиль: 95%
0.19104
Средний

4.3 Medium

CVSS2