Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-3597

Опубликовано: 23 авг. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8

Описание

Multiple buffer overflows in the php_parserr function in ext/standard/dns.c in PHP before 5.4.32 and 5.5.x before 5.5.16 allow remote DNS servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted DNS record, related to the dns_get_record function and the dn_expand function. NOTE: this issue exists because of an incomplete fix for CVE-2014-4049.

РелизСтатусПримечание
devel

released

5.5.12+dfsg-2ubuntu4
esm-infra-legacy/trusty

not-affected

5.5.9+dfsg-1ubuntu4.4
lucid

released

5.3.2-1ubuntu4.27
precise

released

5.3.10-1ubuntu3.14
trusty

released

5.5.9+dfsg-1ubuntu4.4
trusty/esm

not-affected

5.5.9+dfsg-1ubuntu4.4
upstream

needs-triage

Показывать по

EPSS

Процентиль: 92%
0.09558
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

redhat
почти 11 лет назад

Multiple buffer overflows in the php_parserr function in ext/standard/dns.c in PHP before 5.4.32 and 5.5.x before 5.5.16 allow remote DNS servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted DNS record, related to the dns_get_record function and the dn_expand function. NOTE: this issue exists because of an incomplete fix for CVE-2014-4049.

nvd
почти 11 лет назад

Multiple buffer overflows in the php_parserr function in ext/standard/dns.c in PHP before 5.4.32 and 5.5.x before 5.5.16 allow remote DNS servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted DNS record, related to the dns_get_record function and the dn_expand function. NOTE: this issue exists because of an incomplete fix for CVE-2014-4049.

debian
почти 11 лет назад

Multiple buffer overflows in the php_parserr function in ext/standard/ ...

github
около 3 лет назад

Multiple buffer overflows in the php_parserr function in ext/standard/dns.c in PHP before 5.4.32 and 5.5.x before 5.5.16 allow remote DNS servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted DNS record, related to the dns_get_record function and the dn_expand function. NOTE: this issue exists because of an incomplete fix for CVE-2014-4049.

fstec
почти 11 лет назад

Уязвимость программного обеспечения PHP, позволяющая удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 92%
0.09558
Низкий

6.8 Medium

CVSS2