Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-3710

Опубликовано: 05 нояб. 2014
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5

Описание

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

РелизСтатусПримечание
devel

released

1:5.20-1ubuntu2
esm-infra-legacy/trusty

released

1:5.14-2ubuntu3.3
lucid

released

5.03-5ubuntu1.5
precise

released

5.09-2ubuntu0.6
trusty

released

1:5.14-2ubuntu3.3
trusty/esm

released

1:5.14-2ubuntu3.3
upstream

needs-triage

utopic

released

1:5.19-1ubuntu1.2

Показывать по

РелизСтатусПримечание
devel

released

5.5.12+dfsg-2ubuntu5
esm-infra-legacy/trusty

released

5.5.9+dfsg-1ubuntu4.5
lucid

released

5.3.2-1ubuntu4.28
precise

released

5.3.10-1ubuntu3.15
trusty

released

5.5.9+dfsg-1ubuntu4.5
trusty/esm

released

5.5.9+dfsg-1ubuntu4.5
upstream

needs-triage

utopic

released

5.5.12+dfsg-2ubuntu4.1

Показывать по

EPSS

Процентиль: 92%
0.07784
Низкий

5 Medium

CVSS2

Связанные уязвимости

redhat
около 11 лет назад

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

nvd
почти 11 лет назад

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

debian
почти 11 лет назад

The donote function in readelf.c in file through 5.20, as used in the ...

github
больше 3 лет назад

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

oracle-oval
около 11 лет назад

ELSA-2014-1768: php53 security update (IMPORTANT)

EPSS

Процентиль: 92%
0.07784
Низкий

5 Medium

CVSS2