PT-2015-1245 · Php+6 · Php+6

Alexander Cherepanov

·

Published

2015-03-18

·

Updated

2023-05-26

·

CVE-2014-9653

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions file versions prior to 5.22 PHP versions prior to 5.4.37 PHP versions 5.5.x prior to 5.5.21 PHP versions 5.6.x prior to 5.6.5
Description The issue is related to the readelf.c module in the file component, specifically in the Fileinfo component used by PHP. It involves incomplete reading of available data during a pread call, which can be exploited by a remote attacker. This exploitation can lead to a denial of service due to access to uninitialized memory or potentially have other unspecified impacts on the system. The attack can be carried out using a specially crafted ELF file.
Recommendations For file versions prior to 5.22, update to version 5.22 or later. For PHP versions prior to 5.4.37, update to version 5.4.37 or later. For PHP versions 5.5.x prior to 5.5.21, update to version 5.5.21 or later. For PHP versions 5.6.x prior to 5.6.5, update to version 5.6.5 or later.

Fix

DoS

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1329
ALT-PU-2021-2505
ALT-PU-2023-1892
BDU:2015-10226
CESA-2015_2155
CESA-2016_0760
CVE-2014-9653
DLA-204-1
DSA-3196-1
RHSA-2015:2155
RHSA-2015_2155
RHSA-2016:0760
RHSA-2016_0760
SUSE-SU-2017:3048-1
USN-3686-1

Affected Products

Alt Linux
Centos
Php
Red Hat
Suse
Ubuntu
File