Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-9652

Опубликовано: 30 мар. 2015
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5

Описание

The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file.

РелизСтатусПримечание
devel

released

1:5.20-1ubuntu2
esm-infra-legacy/trusty

released

1:5.14-2ubuntu3.3
lucid

not-affected

verified with valgrind
precise

released

5.09-2ubuntu0.6
trusty

released

1:5.14-2ubuntu3.3
trusty/esm

released

1:5.14-2ubuntu3.3
upstream

released

1:5.21+15-1
utopic

released

1:5.19-1ubuntu1.2

Показывать по

РелизСтатусПримечание
devel

released

5.6.4+dfsg-4ubuntu2
esm-infra-legacy/trusty

released

5.5.9+dfsg-1ubuntu4.6
lucid

not-affected

relevant code similar to lucid's file
precise

not-affected

relevant code similar to lucid's file
trusty

released

5.5.9+dfsg-1ubuntu4.6
trusty/esm

released

5.5.9+dfsg-1ubuntu4.6
upstream

released

5.6.5+dfsg-1
utopic

released

5.5.12+dfsg-2ubuntu4.2

Показывать по

EPSS

Процентиль: 90%
0.05795
Низкий

5 Medium

CVSS2

Связанные уязвимости

redhat
почти 11 лет назад

The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file.

nvd
больше 10 лет назад

The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file.

debian
больше 10 лет назад

The mconvert function in softmagic.c in file before 5.21, as used in t ...

github
больше 3 лет назад

The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file.

fstec
почти 12 лет назад

Уязвимость интерпретатора PHP, позволяющая удалённому злоумышленнику получить доступ к области памяти за пределами границ приложения или вызвать аварийное завершение приложения

EPSS

Процентиль: 90%
0.05795
Низкий

5 Medium

CVSS2