CVE-2014-0238
published 2014-06-01CVE-2014-0238: The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial…
PriorityP432medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
20.80%
97.3th percentile
The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (infinite loop or out-of-bounds memory access) via a vector that (1) has zero length or (2) is too long.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | os_x_yosemite_v10.10.3_and_security_update_2015-004 | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | file | < file 1:5.19-1 (bookworm) | file 1:5.19-1 (bookworm) |
| file_project | file | >= 0 < 1:5.19-1 | 1:5.19-1 |
| file_project | file | >= 0 < 1:5.19-1 | 1:5.19-1 |
| file_project | file | >= 0 < 1:5.19-1 | 1:5.19-1 |
| file_project | file | >= 0 < 1:5.19-1 | 1:5.19-1 |
| php | php | < 5.3.29 | 5.3.29 |
| php | php | >= 5.4.0 < 5.4.29 | 5.4.29 |
| php | php | >= 5.5.0 < 5.5.13 | 5.5.13 |
| php5 | php5 | >= 0 < 5.5.9+dfsg-1ubuntu4.2 | 5.5.9+dfsg-1ubuntu4.2 |
| php5 | php5 | >= 0 < 5.5.9+dfsg-1ubuntu4.1 | 5.5.9+dfsg-1ubuntu4.1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.2HIGH
vendor_ubuntu7.2HIGH
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9qpg-75cw-6c38: The cdf_read_property_info function in cdf
ghsa_unreviewed·2022-05-17
CVE-2014-0238 [MEDIUM] CWE-119 GHSA-9qpg-75cw-6c38: The cdf_read_property_info function in cdf
The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (infinite loop or out-of-bounds memory access) via a vector that (1) has zero length or (2) is too long.
OSV
php5 updates
osv·2014-06-25·CVSS 7.2
CVE-2014-0185 [HIGH] php5 updates
php5 updates
USN-2254-1 fixed vulnerabilities in PHP. The fix for CVE-2014-0185
further restricted the permissions on the PHP FastCGI Process Manager (FPM)
UNIX socket. This update grants socket access to the www-data user and
group so installations and documentation relying on the previous socket
permissions will continue to function.
Original advisory details:
Christian Hoffmann discovered that the PHP FastCGI Process Manager (FPM)
set incorrect permissions on the UNIX socket. A local attacker could use
this issue to possibly elevate their privileges. This issue only affected
Ubuntu 12.04 LTS, Ubuntu 13.10, and Ubuntu 14.04 LTS. (CVE-2014-0185)
Francisco Alonso discovered that the PHP Fileinfo component incorrectly
handled certain CDF documents. A remote attacker could use this issue
OSV
php5 vulnerabilities
osv·2014-06-23·CVSS 7.2
CVE-2014-0185 [HIGH] php5 vulnerabilities
php5 vulnerabilities
Christian Hoffmann discovered that the PHP FastCGI Process Manager (FPM)
set incorrect permissions on the UNIX socket. A local attacker could use
this issue to possibly elevate their privileges. This issue only affected
Ubuntu 12.04 LTS, Ubuntu 13.10, and Ubuntu 14.04 LTS. (CVE-2014-0185)
Francisco Alonso discovered that the PHP Fileinfo component incorrectly
handled certain CDF documents. A remote attacker could use this issue to
cause PHP to hang or crash, resulting in a denial of service.
(CVE-2014-0237, CVE-2014-0238)
Stefan Esser discovered that PHP incorrectly handled DNS TXT records. A
remote attacker could use this issue to cause PHP to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2014-4049)
OSV
CVE-2014-0238: The cdf_read_property_info function in cdf
osv·2014-06-01·CVSS 5.0
CVE-2014-0238 [MEDIUM] CVE-2014-0238: The cdf_read_property_info function in cdf
The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (infinite loop or out-of-bounds memory access) via a vector that (1) has zero length or (2) is too long.
Ubuntu
PHP updates
vendor_ubuntu·2014-06-25·CVSS 7.2
CVE-2014-0185 [HIGH] PHP updates
Title: PHP updates
Summary: An improvement was made for PHP FPM environments.
USN-2254-1 fixed vulnerabilities in PHP. The fix for CVE-2014-0185
further restricted the permissions on the PHP FastCGI Process Manager (FPM)
UNIX socket. This update grants socket access to the www-data user and
group so installations and documentation relying on the previous socket
permissions will continue to function.
Original advisory details:
Christian Hoffmann discovered that the PHP FastCGI Process Manager (FPM)
set incorrect permissions on the UNIX socket. A local attacker could use
this issue to possibly elevate their privileges. This issue only affected
Ubuntu 12.04 LTS, Ubuntu 13.10, and Ubuntu 14.04 LTS. (CVE-2014-0185)
Francisco Alonso discovered that the PHP Fileinfo component incorrectly
han
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2014-06-23·CVSS 7.2
CVE-2014-0185 [HIGH] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
Christian Hoffmann discovered that the PHP FastCGI Process Manager (FPM)
set incorrect permissions on the UNIX socket. A local attacker could use
this issue to possibly elevate their privileges. This issue only affected
Ubuntu 12.04 LTS, Ubuntu 13.10, and Ubuntu 14.04 LTS. (CVE-2014-0185)
Francisco Alonso discovered that the PHP Fileinfo component incorrectly
handled certain CDF documents. A remote attacker could use this issue to
cause PHP to hang or crash, resulting in a denial of service.
(CVE-2014-0237, CVE-2014-0238)
Stefan Esser discovered that PHP incorrectly handled DNS TXT records. A
remote attacker could use this issue to cause PHP to crash, resulting in a
denial of service, or possibly execute arb
Red Hat
file: CDF property info parsing nelements infinite loop
vendor_redhat·2014-05-29·CVSS 5.0
CVE-2014-0238 [MEDIUM] CWE-835 file: CDF property info parsing nelements infinite loop
file: CDF property info parsing nelements infinite loop
The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (infinite loop or out-of-bounds memory access) via a vector that (1) has zero length or (2) is too long.
A denial of service flaw was found in the way the File Information (fileinfo) extension parsed certain Composite Document Format (CDF) files. A remote attacker could use this flaw to crash a PHP application using fileinfo via a specially crafted CDF file.
Statement: This issue did not affect the php and the file packages as shipped with Red Hat Enterprise Linux 5.
This issue affects the versions of file as shipped with Red Hat Enterprise Linux 7. Red Hat Product
Debian
CVE-2014-0238: file - The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP be...
vendor_debian·2014·CVSS 5.0
CVE-2014-0238 [MEDIUM] CVE-2014-0238: file - The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP be...
The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (infinite loop or out-of-bounds memory access) via a vector that (1) has zero length or (2) is too long.
Scope: local
bookworm: resolved (fixed in 1:5.19-1)
bullseye: resolved (fixed in 1:5.19-1)
forky: resolved (fixed in 1:5.19-1)
sid: resolved (fixed in 1:5.19-1)
trixie: resolved (fixed in 1:5.19-1)
Apple
CVE-2014-0238: OS X Yosemite v10.10.3 and Security Update 2015-004
vendor_apple·CVSS 5.0
CVE-2014-0238 [MEDIUM] CVE-2014-0238: OS X Yosemite v10.10.3 and Security Update 2015-004
Apple Security Update: About the security content of OS X Yosemite v10.10.3 and Security Update 2015-004
Product: OS X Yosemite v10.10.3 and Security Update 2015-004
CVE: CVE-2014-0238
Component: CVE-2014-0238
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0237 CVE-2014-0238 file: various flaws [fedora-all]
bugzilla·2014-06-02·CVSS 5.0
CVE-2014-0237 [MEDIUM] CVE-2014-0237 CVE-2014-0238 file: various flaws [fedora-all]
CVE-2014-0237 CVE-2014-0238 file: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple supported version
Bugzilla
CVE-2014-0237 CVE-2014-0238 php: various flaws [fedora-all]
bugzilla·2014-06-02·CVSS 5.0
CVE-2014-0237 [MEDIUM] CVE-2014-0237 CVE-2014-0238 php: various flaws [fedora-all]
CVE-2014-0237 CVE-2014-0238 php: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2014-0237 file: cdf_unpack_summary_info() excessive looping DoS
bugzilla·2014-05-15·CVSS 5.0
CVE-2014-0237 [MEDIUM] CVE-2014-0237 file: cdf_unpack_summary_info() excessive looping DoS
CVE-2014-0237 file: cdf_unpack_summary_info() excessive looping DoS
A flaw was found in the way file's Composite Document Files (CDF) format parser handle CDF files with many summary info entries. The cdf_unpack_summary_info() function unnecessarily repeatedly read the info from the same offset. This led to many file_printf() calls in cdf_file_property_info(), which caused file to use an excessive amount of CPU time when parsing a specially-crafted CDF file.
Discussion:
PHP bug https://bugs.php.net/bug.php?id=67328
---
Upstream commit:
https://github.com/file/file/commit/b8acc83781d5a24cc5101e525d15efe0482c280d
---
PHP commit in 5.4.29
http://git.php.net/?p=php-src.git;a=commit;h=68ce2d0ea6da79b12a365e375e1c2ce882c77480
---
Public now: http://www.php.net/ChangeLog-5.php#5.5.13
--
Bugzilla
CVE-2014-0238 file: CDF property info parsing nelements infinite loop
bugzilla·2014-05-15·CVSS 5.0
CVE-2014-0238 [MEDIUM] CVE-2014-0238 file: CDF property info parsing nelements infinite loop
CVE-2014-0238 file: CDF property info parsing nelements infinite loop
A flaw was found in the way file parsed property information from Composite Document Files (CDF) files. A property entry with 0 elements triggers an infinite loop.
The problem is in cdf_read_property_info() function in src/cdf.c:
https://github.com/file/file/blob/FILE5_18/src/cdf.c#L742
A for loop with counter i is used to loop through properties. Inside it, nelements value is read from the input file. For string type properties, there is additional nested for loop with counter j, which also increments counter i of the outer for loop.
https://github.com/file/file/blob/FILE5_18/src/cdf.c#L890
In cdf.c:
801 for (i = 0; i < sh.sh_properties; i++) {
..
814 if (inp[i].pi_type & CDF_VECTOR) {
815 nelements = CDF_GETUINT32
http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-07/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1765.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1766.htmlhttp://secunia.com/advisories/59061http://secunia.com/advisories/59329http://secunia.com/advisories/59418http://secunia.com/advisories/60998http://support.apple.com/kb/HT6443http://www-01.ibm.com/support/docview.wss?uid=swg21683486http://www.debian.org/security/2014/dsa-3021http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.php.net/ChangeLog-5.phphttp://www.securityfocus.com/bid/67765https://bugs.php.net/bug.php?id=67327https://github.com/file/file/commit/f97486ef5dc3e8735440edc4fc8808c63e1a3ef0https://support.apple.com/HT204659http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-07/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1765.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1766.htmlhttp://secunia.com/advisories/59061http://secunia.com/advisories/59329http://secunia.com/advisories/59418http://secunia.com/advisories/60998http://support.apple.com/kb/HT6443http://www-01.ibm.com/support/docview.wss?uid=swg21683486http://www.debian.org/security/2014/dsa-3021http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.php.net/ChangeLog-5.phphttp://www.securityfocus.com/bid/67765https://bugs.php.net/bug.php?id=67327https://github.com/file/file/commit/f97486ef5dc3e8735440edc4fc8808c63e1a3ef0https://support.apple.com/HT204659
2014-06-01
Published