PT-2014-2044 · Php+4 · Php+4

Publicado

2014-07-18

·

Atualizado

2024-06-15

·

CVE-2014-3670

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.4.34 PHP versions 5.5.x prior to 5.5.18 PHP versions 5.6.x prior to 5.6.2
Description The issue is caused by a buffer overflow in the PHP language interpreter extension. It may allow a remote attacker to execute arbitrary code or cause a denial of service through a crafted JPEG image with TIFF thumbnail data. The exif ifd make value function in exif.c operates on floating-point arrays incorrectly, leading to heap memory corruption and application crash.
Recommendations For PHP versions prior to 5.4.34, update to version 5.4.34 or later. For PHP versions 5.5.x prior to 5.5.18, update to version 5.5.18 or later. For PHP versions 5.6.x prior to 5.6.2, update to version 5.6.2 or later. As a temporary workaround, consider restricting the handling of JPEG images with TIFF thumbnail data to minimize the risk of exploitation.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-02650
CESA-2014_1767
CVE-2014-3670
DLA-94-1
DSA-3064-1
MGASA-2014-0430
OPENSUSE-SU-2024:10290-1
OPENSUSE-SU-2024:10344-1
OPENSUSE-SU-2024:11169-1
RHSA-2014:1765
RHSA-2014:1766
RHSA-2014:1767
RHSA-2014:1768
RHSA-2014:1824
RHSA-2014_1767
RHSA-2014_1768
RHSA-2014_1824
RHSA-2015:0021
SUSE-SU-2016:1638-1
USN-2391-1

Produtos afetados

Centos
Php
Red Hat
Suse
Ubuntu