PT-2014-1305 · Php+5 · Php+5

Remi

·

Published

2014-06-01

·

Updated

2024-06-15

·

CVE-2014-0238

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions file-static-5.04 versions 5.04 file-devel-5.04 versions 5.04 file versions prior to 5.04 file-debuginfo-5.04 versions 5.04 file-libs-5.04 versions 5.04 PHP versions prior to 5.4.29 and 5.5.x prior to 5.5.13
Description The issue concerns multiple vulnerabilities in the file package of various operating systems, including Red Hat Enterprise Linux and Debian GNU/Linux, which can lead to disruption of protected information availability. These vulnerabilities can be exploited remotely. Additionally, a vulnerability in the cdf read property info function in the cdf.c component of PHP's Fileinfo allows remote attackers to cause a denial of service via specially crafted CDF files, potentially resulting in an infinite loop or out-of-bounds memory access.
Recommendations For file-static-5.04 version 5.04, update to a version that contains a fix for this issue. For file-devel-5.04 version 5.04, update to a version that contains a fix for this issue. For file versions prior to 5.04, update to version 5.04 or later. For file-debuginfo-5.04 version 5.04, update to a version that contains a fix for this issue. For file-libs-5.04 version 5.04, update to a version that contains a fix for this issue. For PHP versions prior to 5.4.29, update to version 5.4.29 or later. For PHP versions 5.5.x prior to 5.5.13, update to version 5.5.13 or later. As a temporary workaround, consider restricting access to the cdf read property info function in PHP until a patch is available.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00090
BDU:2015-01282
BDU:2015-06092
BDU:2015-06093
BDU:2015-06094
BDU:2015-06095
BDU:2015-06096
CESA-2014_1012
CESA-2014_1013
CESA-2014_1606
CESA-2015_2155
CVE-2014-0238
DLA-145-1
DLA-27-1
DSA-2943-1
DSA-3021-1
MGASA-2014-0252
MGASA-2014-0258
OPENSUSE-SU-2024:10290-1
OPENSUSE-SU-2024:10344-1
OPENSUSE-SU-2024:11169-1
RHSA-2014:1012
RHSA-2014:1013
RHSA-2014:1606
RHSA-2014:1765
RHSA-2014:1766
RHSA-2014_1012
RHSA-2014_1013
RHSA-2014_1606
RHSA-2015:2155
RHSA-2015_2155
SUSE-SU-2015:0370-1
SUSE-SU-2015:0436-1
SUSE-SU-2015:1018-1
SUSE-SU-2015:1265-1
USN-2254-1
USN-2254-2

Affected Products

Centos
Debian
Php
Red Hat
Suse
Ubuntu