CVE
- Id
- 70883
- CVE No.
- CVE-2014-3587
- Status
- Candidate
- Description
- Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1571.
- Phase
- Assigned (20140514)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
675239 | 70883 | CVE-2014-3587 | CONFIRM:http://php.net/ChangeLog-5.php | View |
675240 | 70883 | CVE-2014-3587 | CONFIRM:https://bugs.php.net/bug.php?id=67716 | View |
675241 | 70883 | CVE-2014-3587 | CONFIRM:https://github.com/file/file/commit/0641e56be1af003aa02c7c6b0184466540637233 | View |
675242 | 70883 | CVE-2014-3587 | CONFIRM:https://github.com/php/php-src/commit/7ba1409a1aee5925180de546057ddd84ff267947 | View |
675243 | 70883 | CVE-2014-3587 | CONFIRM:https://security-tracker.debian.org/tracker/CVE-2014-3587 | View |
675244 | 70883 | CVE-2014-3587 | CONFIRM:https://support.apple.com/HT204659 | View |
675245 | 70883 | CVE-2014-3587 | CONFIRM:http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html | View |
675246 | 70883 | CVE-2014-3587 | CONFIRM:http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html | View |
675247 | 70883 | CVE-2014-3587 | CONFIRM:http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html | View |
675248 | 70883 | CVE-2014-3587 | APPLE:APPLE-SA-2015-04-08-2 | View |
675249 | 70883 | CVE-2014-3587 | URL:http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html | View |
675250 | 70883 | CVE-2014-3587 | DEBIAN:DSA-3008 | View |
675251 | 70883 | CVE-2014-3587 | URL:http://www.debian.org/security/2014/dsa-3008 | View |
675252 | 70883 | CVE-2014-3587 | DEBIAN:DSA-3021 | View |
675253 | 70883 | CVE-2014-3587 | URL:http://www.debian.org/security/2014/dsa-3021 | View |
675254 | 70883 | CVE-2014-3587 | REDHAT:RHSA-2014:1326 | View |
675255 | 70883 | CVE-2014-3587 | URL:http://rhn.redhat.com/errata/RHSA-2014-1326.html | View |
675256 | 70883 | CVE-2014-3587 | REDHAT:RHSA-2014:1327 | View |
675257 | 70883 | CVE-2014-3587 | URL:http://rhn.redhat.com/errata/RHSA-2014-1327.html | View |
675258 | 70883 | CVE-2014-3587 | REDHAT:RHSA-2014:1765 | View |
675259 | 70883 | CVE-2014-3587 | URL:http://rhn.redhat.com/errata/RHSA-2014-1765.html | View |
675260 | 70883 | CVE-2014-3587 | REDHAT:RHSA-2014:1766 | View |
675261 | 70883 | CVE-2014-3587 | URL:http://rhn.redhat.com/errata/RHSA-2014-1766.html | View |
675262 | 70883 | CVE-2014-3587 | UBUNTU:USN-2344-1 | View |
675263 | 70883 | CVE-2014-3587 | URL:http://www.ubuntu.com/usn/USN-2344-1 | View |
675264 | 70883 | CVE-2014-3587 | UBUNTU:USN-2369-1 | View |
675265 | 70883 | CVE-2014-3587 | URL:http://www.ubuntu.com/usn/USN-2369-1 | View |
675266 | 70883 | CVE-2014-3587 | BID:69325 | View |
675267 | 70883 | CVE-2014-3587 | URL:http://www.securityfocus.com/bid/69325 | View |
675268 | 70883 | CVE-2014-3587 | SECUNIA:60609 | View |
675269 | 70883 | CVE-2014-3587 | URL:http://secunia.com/advisories/60609 | View |
675270 | 70883 | CVE-2014-3587 | SECUNIA:60696 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
15521 | JVNDB-2014-004396 | Spacewalk の spacewalk-java および Red Hat Network Satellite におけるクロスサイトスクリプティングの脆弱性 | Spacewalk の spacewalk-java および Red Hat Network (RHN) Satellite には、クロスサイトスクリプティングの脆弱性が存在します。 | CVE-2014-3595 | 70883 | 4.3 | http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-004396.html | View |