PT-2014-2039 · Php+4 · Php+5

Publicado

2014-07-18

·

Atualizado

2024-06-15

·

CVE-2014-3668

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.4.34 PHP versions 5.5.x prior to 5.5.18 PHP versions 5.6.x prior to 5.6.2
Description The issue is caused by a buffer overflow in the date from ISO8601 function in the mkgmtime implementation in libxmlrpc/xmlrpc.c in the XMLRPC extension. This allows remote attackers to cause a denial of service (application crash) via a crafted first argument to the xmlrpc set type function or a crafted argument to the xmlrpc decode function, related to an out-of-bounds read operation.
Recommendations For PHP versions prior to 5.4.34, update to version 5.4.34 or later. For PHP versions 5.5.x prior to 5.5.18, update to version 5.5.18 or later. For PHP versions 5.6.x prior to 5.6.2, update to version 5.6.2 or later.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-02643
CESA-2014_1767
CVE-2014-3668
DLA-94-1
DSA-3064-1
OPENSUSE-SU-2024:10290-1
OPENSUSE-SU-2024:10344-1
OPENSUSE-SU-2024:11169-1
RHSA-2014:1765
RHSA-2014:1766
RHSA-2014:1767
RHSA-2014:1768
RHSA-2014_1767
RHSA-2014_1768
SUSE-SU-2014_1441-1
SUSE-SU-2014_1497-1
SUSE-SU-2016:1638-1
USN-2391-1

Produtos afetados

Centos
Php
Red Hat
Suse
Ubuntu
Libxmlrpc