Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-9653

Опубликовано: 30 мар. 2015
Источник: ubuntu
Приоритет: low
CVSS2: 7.5

Описание

readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory access) or possibly have unspecified other impact via a crafted ELF file.

РелизСтатусПримечание
artful

not-affected

1:5.25-2ubuntu1
bionic

not-affected

1:5.25-2ubuntu1
cosmic

not-affected

1:5.25-2ubuntu1
devel

not-affected

1:5.25-2ubuntu1
disco

not-affected

1:5.25-2ubuntu1
eoan

not-affected

1:5.25-2ubuntu1
esm-infra-legacy/trusty

not-affected

1:5.14-2ubuntu3.4
esm-infra/bionic

not-affected

1:5.25-2ubuntu1
esm-infra/focal

not-affected

1:5.25-2ubuntu1
esm-infra/xenial

not-affected

1:5.25-2ubuntu1

Показывать по

РелизСтатусПримечание
artful

DNE

bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-infra-legacy/trusty

not-affected

esm-infra/focal

DNE

focal

DNE

groovy

DNE

Показывать по

7.5 High

CVSS2

Связанные уязвимости

redhat
больше 10 лет назад

readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory access) or possibly have unspecified other impact via a crafted ELF file.

nvd
около 10 лет назад

readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory access) or possibly have unspecified other impact via a crafted ELF file.

debian
около 10 лет назад

readelf.c in file before 5.22, as used in the Fileinfo component in PH ...

github
около 3 лет назад

readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory access) or possibly have unspecified other impact via a crafted ELF file.

fstec
около 10 лет назад

Уязвимость интерпретатора PHP, позволяющая удалённому нарушителю вызвать отказ в обслуживании или оказать иное воздействие на систему

7.5 High

CVSS2