PT-2015-1245 · Php+6 · Php+6

Alexander Cherepanov

·

Publicado

2015-03-18

·

Atualizado

2023-05-26

·

CVE-2014-9653

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions file versions prior to 5.22 PHP versions prior to 5.4.37 PHP versions 5.5.x prior to 5.5.21 PHP versions 5.6.x prior to 5.6.5
Description The issue is related to the readelf.c module in the file component, specifically in the Fileinfo component used by PHP. It involves incomplete reading of available data during a pread call, which can be exploited by a remote attacker. This exploitation can lead to a denial of service due to access to uninitialized memory or potentially have other unspecified impacts on the system. The attack can be carried out using a specially crafted ELF file.
Recommendations For file versions prior to 5.22, update to version 5.22 or later. For PHP versions prior to 5.4.37, update to version 5.4.37 or later. For PHP versions 5.5.x prior to 5.5.21, update to version 5.5.21 or later. For PHP versions 5.6.x prior to 5.6.5, update to version 5.6.5 or later.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1329
ALT-PU-2021-2505
ALT-PU-2023-1892
BDU:2015-10226
CESA-2015_2155
CESA-2016_0760
CVE-2014-9653
DLA-204-1
DSA-3196-1
RHSA-2015:2155
RHSA-2015_2155
RHSA-2016:0760
RHSA-2016_0760
SUSE-SU-2017:3048-1
USN-3686-1

Produtos afetados

Alt Linux
Centos
Php
Red Hat
Suse
Ubuntu
File