Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-9652

Опубликовано: 30 мар. 2015
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5

Описание

The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file.

РелизСтатусПримечание
devel

released

1:5.20-1ubuntu2
esm-infra-legacy/trusty

not-affected

1:5.14-2ubuntu3.3
lucid

not-affected

verified with valgrind
precise

released

5.09-2ubuntu0.6
trusty

released

1:5.14-2ubuntu3.3
trusty/esm

not-affected

1:5.14-2ubuntu3.3
upstream

released

1:5.21+15-1
utopic

released

1:5.19-1ubuntu1.2

Показывать по

РелизСтатусПримечание
devel

released

5.6.4+dfsg-4ubuntu2
esm-infra-legacy/trusty

not-affected

5.5.9+dfsg-1ubuntu4.6
lucid

not-affected

relevant code similar to lucid's file
precise

not-affected

relevant code similar to lucid's file
trusty

released

5.5.9+dfsg-1ubuntu4.6
trusty/esm

not-affected

5.5.9+dfsg-1ubuntu4.6
upstream

released

5.6.5+dfsg-1
utopic

released

5.5.12+dfsg-2ubuntu4.2

Показывать по

EPSS

Процентиль: 90%
0.06004
Низкий

5 Medium

CVSS2

Связанные уязвимости

redhat
больше 10 лет назад

The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file.

nvd
около 10 лет назад

The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file.

debian
около 10 лет назад

The mconvert function in softmagic.c in file before 5.21, as used in t ...

github
около 3 лет назад

The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file.

fstec
больше 11 лет назад

Уязвимость интерпретатора PHP, позволяющая удалённому злоумышленнику получить доступ к области памяти за пределами границ приложения или вызвать аварийное завершение приложения

EPSS

Процентиль: 90%
0.06004
Низкий

5 Medium

CVSS2