|
|
Log in / Subscribe / Register

php5: denial of service

Package(s):php5 CVE #(s):CVE-2014-0237 CVE-2014-0238
Created:June 2, 2014 Updated:July 7, 2014
Description: From the CVE entries:

The cdf_unpack_summary_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (performance degradation) by triggering many file_printf calls. (CVE-2014-0237)

The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (infinite loop or out-of-bounds memory access) via a vector that (1) has zero length or (2) is too long. (CVE-2014-0238)

Alerts:
Scientific Linux SLSA-2015:2155-7 file 2015-12-21
Oracle ELSA-2015-2155 file 2015-11-23
Red Hat RHSA-2015:2155-07 file 2015-11-19
Mandriva MDVSA-2015:080 php 2015-03-28
Debian-LTS DLA-145-1 php5 2015-01-31
Scientific Linux SLSA-2014:1606-2 file 2014-11-03
Red Hat RHSA-2014:1766-01 php55-php 2014-10-30
Red Hat RHSA-2014:1765-01 php54-php 2014-10-30
Red Hat RHSA-2014:1606-02 file 2014-10-14
Debian DSA-3021-2 file 2014-09-10
Debian DSA-3021-1 file 2014-09-09
Gentoo 201408-11 php 2014-08-29
Oracle ELSA-2014-1606 file 2014-10-16
Scientific Linux SLSA-2014:1012-1 php53 and php 2014-08-06
CentOS CESA-2014:1013 php 2014-08-06
CentOS CESA-2014:1012 php53 2014-08-06
Oracle ELSA-2014-1013 php 2014-08-06
Oracle ELSA-2014-1012 php53 2014-08-06
Oracle ELSA-2014-1012 php53 2014-08-06
CentOS CESA-2014:1012 php53 2014-08-06
Red Hat RHSA-2014:1012-01 php53 2014-08-06
Fedora FEDORA-2014-7992 file 2014-07-05
SUSE SUSE-SU-2014:0869-1 php53 2014-07-04
Red Hat RHSA-2014:1013-01 php 2014-08-06
Ubuntu USN-2254-2 php5 2014-06-25
Ubuntu USN-2254-1 php5 2014-06-23
Fedora FEDORA-2014-6904 php-phpunit-PHPUnit-MockObject 2014-06-17
Fedora FEDORA-2014-6901 php-phpunit-PHPUnit-MockObject 2014-06-17
Fedora FEDORA-2014-6904 php-doctrine-orm 2014-06-17
Fedora FEDORA-2014-6901 php-doctrine-orm 2014-06-17
Fedora FEDORA-2014-6904 php 2014-06-17
Fedora FEDORA-2014-6901 php 2014-06-17
Slackware SSA:2014-160-01 php 2014-06-09
Mandriva MDVSA-2014:115 php 2014-06-10
Mageia MGASA-2014-0258 php 2014-06-06
Mageia MGASA-2014-0252 file 2014-06-06
Debian DSA-2943-1 php5 2014-06-01
Mandriva MDVSA-2014:116 file 2014-06-10
openSUSE openSUSE-SU-2014:0786-1 php5 2014-06-12
openSUSE openSUSE-SU-2014:0784-1 php5 2014-06-12

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds