Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-3597

Опубликовано: 23 авг. 2014
Источник: ubuntu
Приоритет: medium
CVSS2: 6.8

Описание

Multiple buffer overflows in the php_parserr function in ext/standard/dns.c in PHP before 5.4.32 and 5.5.x before 5.5.16 allow remote DNS servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted DNS record, related to the dns_get_record function and the dn_expand function. NOTE: this issue exists because of an incomplete fix for CVE-2014-4049.

РелизСтатусПримечание
devel

released

5.5.12+dfsg-2ubuntu4
esm-infra-legacy/trusty

released

5.5.9+dfsg-1ubuntu4.4
lucid

released

5.3.2-1ubuntu4.27
precise

released

5.3.10-1ubuntu3.14
trusty

released

5.5.9+dfsg-1ubuntu4.4
trusty/esm

released

5.5.9+dfsg-1ubuntu4.4
upstream

needs-triage

Показывать по

6.8 Medium

CVSS2

Связанные уязвимости

redhat
больше 11 лет назад

Multiple buffer overflows in the php_parserr function in ext/standard/dns.c in PHP before 5.4.32 and 5.5.x before 5.5.16 allow remote DNS servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted DNS record, related to the dns_get_record function and the dn_expand function. NOTE: this issue exists because of an incomplete fix for CVE-2014-4049.

nvd
около 11 лет назад

Multiple buffer overflows in the php_parserr function in ext/standard/dns.c in PHP before 5.4.32 and 5.5.x before 5.5.16 allow remote DNS servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted DNS record, related to the dns_get_record function and the dn_expand function. NOTE: this issue exists because of an incomplete fix for CVE-2014-4049.

debian
около 11 лет назад

Multiple buffer overflows in the php_parserr function in ext/standard/ ...

github
больше 3 лет назад

Multiple buffer overflows in the php_parserr function in ext/standard/dns.c in PHP before 5.4.32 and 5.5.x before 5.5.16 allow remote DNS servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted DNS record, related to the dns_get_record function and the dn_expand function. NOTE: this issue exists because of an incomplete fix for CVE-2014-4049.

fstec
около 11 лет назад

Уязвимость программного обеспечения PHP, позволяющая удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

6.8 Medium

CVSS2