CVE-2014-3487

EUVD-2014-3494
The cdf_read_property_info function in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate a stream offset, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
Affected Products (NVD)
VendorProductVersion
file_projectfile
𝑥
< 5.19
phpphp
𝑥
< 5.3.29
phpphp
5.4.0 ≤
𝑥
< 5.4.30
phpphp
5.5.0 ≤
𝑥
< 5.5.14
debiandebian_linux
7.0
debiandebian_linux
8.0
opensuseopensuse
11.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
file
bookworm
1:5.44-3
fixed
bullseye
1:5.39-3+deb11u1
fixed
bullseye (security)
1:5.39-3+deb11u1
fixed
sid
1:5.45-3
fixed
squeeze
not-affected
trixie
1:5.45-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
file
lucid
Fixed 5.03-5ubuntu1.3
released
precise
Fixed 5.09-2ubuntu0.4
released
saucy
Fixed 5.11-2ubuntu4.3
released
trusty
Fixed 1:5.14-2ubuntu3.1
released
php5
lucid
not-affected
precise
not-affected
saucy
Fixed 5.5.3+dfsg-1ubuntu2.6
released
trusty
Fixed 5.5.9+dfsg-1ubuntu4.3
released
References