CVE-2014-3478
published 2014-07-09CVE-2014-3478: Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14…
PriorityP432medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
15.18%
96.4th percentile
Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (application crash) via a crafted Pascal string in a FILE_PSTRING conversion.
Affected
71 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | os_x_yosemite_v10.10.3_and_security_update_2015-004 | — | — |
| christos_zoulas | file | <= 5.18 | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| debian | file | < file 1:5.19-1 (bookworm) | file 1:5.19-1 (bookworm) |
| file_project | file | >= 0 < 1:5.19-1 | 1:5.19-1 |
| file_project | file | >= 0 < 1:5.19-1 | 1:5.19-1 |
| file_project | file | >= 0 < 1:5.19-1 | 1:5.19-1 |
| file_project | file | >= 0 < 1:5.19-1 | 1:5.19-1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h772-f5rg-qrvv: Buffer overflow in the mconvert function in softmagic
ghsa_unreviewed·2022-05-17
CVE-2014-3478 [MEDIUM] CWE-119 GHSA-h772-f5rg-qrvv: Buffer overflow in the mconvert function in softmagic
Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (application crash) via a crafted Pascal string in a FILE_PSTRING conversion.
OSV
file vulnerabilities
osv·2014-07-15·CVSS 5.0
CVE-2013-7345 [MEDIUM] file vulnerabilities
file vulnerabilities
Mike Frysinger discovered that the file awk script detector used multiple
wildcard with unlimited repetitions. An attacker could use this issue to
cause file to consume resources, resulting in a denial of service.
(CVE-2013-7345)
Francisco Alonso discovered that file incorrectly handled certain CDF
documents. A attacker could use this issue to cause file to hang or crash,
resulting in a denial of service. (CVE-2014-0207, CVE-2014-3478,
CVE-2014-3479, CVE-2014-3480, CVE-2014-3487)
Jan Kaluža discovered that file did not properly restrict the amount of
data read during regex searches. An attacker could use this issue to
cause file to consume resources, resulting in a denial of service.
(CVE-2014-3538)
OSV
CVE-2014-3478: Buffer overflow in the mconvert function in softmagic
osv·2014-07-09·CVSS 6.5
CVE-2014-3478 [MEDIUM] CVE-2014-3478: Buffer overflow in the mconvert function in softmagic
Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (application crash) via a crafted Pascal string in a FILE_PSTRING conversion.
OSV
php5 vulnerabilities
osv·2014-07-09·CVSS 6.5
CVE-2014-0207 [MEDIUM] php5 vulnerabilities
php5 vulnerabilities
Francisco Alonso discovered that the PHP Fileinfo component incorrectly
handled certain CDF documents. A remote attacker could use this issue to
cause PHP to hang or crash, resulting in a denial of service.
(CVE-2014-0207, CVE-2014-3478, CVE-2014-3479, CVE-2014-3480, CVE-2014-3487)
Stefan Esser discovered that PHP incorrectly handled unserializing SPL
extension objects. An attacker could use this issue to execute arbitrary
code. (CVE-2014-3515)
It was discovered that PHP incorrectly handled certain SPL Iterators. An
attacker could use this issue to cause PHP to crash, resulting in a denial
of service. (CVE-2014-4670)
It was discovered that PHP incorrectly handled certain ArrayIterators. An
attacker could use this issue to cause PHP to crash, resulting in a denial
o
Ubuntu
file vulnerabilities
vendor_ubuntu·2014-07-15·CVSS 5.0
CVE-2013-7345 [MEDIUM] file vulnerabilities
Title: file vulnerabilities
Summary: File could be made to crash or hang if it processed specially crafted data.
Mike Frysinger discovered that the file awk script detector used multiple
wildcard with unlimited repetitions. An attacker could use this issue to
cause file to consume resources, resulting in a denial of service.
(CVE-2013-7345)
Francisco Alonso discovered that file incorrectly handled certain CDF
documents. A attacker could use this issue to cause file to hang or crash,
resulting in a denial of service. (CVE-2014-0207, CVE-2014-3478,
CVE-2014-3479, CVE-2014-3480, CVE-2014-3487)
Jan Kaluža discovered that file did not properly restrict the amount of
data read during regex searches. An attacker could use this issue to
cause file to consume resources, resulting in a denial of
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2014-07-09·CVSS 6.5
CVE-2014-0207 [MEDIUM] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
Francisco Alonso discovered that the PHP Fileinfo component incorrectly
handled certain CDF documents. A remote attacker could use this issue to
cause PHP to hang or crash, resulting in a denial of service.
(CVE-2014-0207, CVE-2014-3478, CVE-2014-3479, CVE-2014-3480, CVE-2014-3487)
Stefan Esser discovered that PHP incorrectly handled unserializing SPL
extension objects. An attacker could use this issue to execute arbitrary
code. (CVE-2014-3515)
It was discovered that PHP incorrectly handled certain SPL Iterators. An
attacker could use this issue to cause PHP to crash, resulting in a denial
of service. (CVE-2014-4670)
It was discovered that PHP incorrectly handled certain ArrayIterators. An
attacker could us
Red Hat
file: mconvert incorrect handling of truncated pascal string size
vendor_redhat·2014-06-27·CVSS 6.5
CVE-2014-3478 [MEDIUM] file: mconvert incorrect handling of truncated pascal string size
file: mconvert incorrect handling of truncated pascal string size
Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (application crash) via a crafted Pascal string in a FILE_PSTRING conversion.
A buffer overflow flaw was found in the way the File Information (fileinfo) extension processed certain Pascal strings. A remote attacker able to make a PHP application using fileinfo convert a specially crafted Pascal string provided by an image file could cause that application to crash.
Statement: This issue did not affect the versions of file, php, and php53 as shipped with Red Hat Enterprise Linux 5 and 6.
This issue affects the versi
Debian
CVE-2014-3478: file - Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as ...
vendor_debian·2014·CVSS 6.5
CVE-2014-3478 [MEDIUM] CVE-2014-3478: file - Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as ...
Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (application crash) via a crafted Pascal string in a FILE_PSTRING conversion.
Scope: local
bookworm: resolved (fixed in 1:5.19-1)
bullseye: resolved (fixed in 1:5.19-1)
forky: resolved (fixed in 1:5.19-1)
sid: resolved (fixed in 1:5.19-1)
trixie: resolved (fixed in 1:5.19-1)
Apple
CVE-2014-3478: OS X Yosemite v10.10.3 and Security Update 2015-004
vendor_apple·CVSS 6.5
CVE-2014-3478 [MEDIUM] CVE-2014-3478: OS X Yosemite v10.10.3 and Security Update 2015-004
Apple Security Update: About the security content of OS X Yosemite v10.10.3 and Security Update 2015-004
Product: OS X Yosemite v10.10.3 and Security Update 2015-004
CVE: CVE-2014-3478
Component: CVE-2014-3478
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3478 file: mconvert incorrect handling of truncated pascal string size [fedora-all]
bugzilla·2014-06-30·CVSS 6.5
CVE-2014-3478 [MEDIUM] CVE-2014-3478 file: mconvert incorrect handling of truncated pascal string size [fedora-all]
CVE-2014-3478 file: mconvert incorrect handling of truncated pascal string size [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue af
Bugzilla
CVE-2014-3478 php: file: mconvert incorrect handling of truncated pascal string size [fedora-all]
bugzilla·2014-06-30·CVSS 6.5
CVE-2014-3478 [MEDIUM] CVE-2014-3478 php: file: mconvert incorrect handling of truncated pascal string size [fedora-all]
CVE-2014-3478 php: file: mconvert incorrect handling of truncated pascal string size [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this iss
Bugzilla
CVE-2014-3478 file: mconvert incorrect handling of truncated pascal string size
bugzilla·2014-06-04·CVSS 6.5
CVE-2014-3478 [MEDIUM] CVE-2014-3478 file: mconvert incorrect handling of truncated pascal string size
CVE-2014-3478 file: mconvert incorrect handling of truncated pascal string size
A flaw was found in the way file compute the truncated pascal string size in mconvert() function.
Upstream commit:
https://github.com/file/file/commit/27a14bc7ba285a0a5ebfdb55e54001aa11932b08
Acknowledgment:
This issue was discovered by Francisco Alonso of Red Hat Product Security.
Discussion:
PHP commit:
http://git.php.net/?p=php-src.git;a=commit;h=e77659a8c87272e5061738a31430d2111482c426
---
Created php tracking bugs for this issue:
Affects: fedora-all [bug 1114450]
---
Created file tracking bugs for this issue:
Affects: fedora-all [bug 1114448]
---
file-5.19-1.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
---
S
Tenable
[R6] SecurityCenter Affected by Multiple Third-party Library Vulnerabilities
blogs_tenable·2014-07-16
[R6] SecurityCenter Affected by Multiple Third-party Library Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2014-09/msg00046.htmlhttp://marc.info/?l=bugtraq&m=141017844705317&w=2http://mx.gw.com/pipermail/file/2014/001553.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1327.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1765.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1766.htmlhttp://secunia.com/advisories/59794http://secunia.com/advisories/59831http://support.apple.com/kb/HT6443http://www.debian.org/security/2014/dsa-2974http://www.debian.org/security/2014/dsa-3021http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.php.net/ChangeLog-5.phphttp://www.securityfocus.com/bid/68239https://bugs.php.net/bug.php?id=67410https://github.com/file/file/commit/27a14bc7ba285a0a5ebfdb55e54001aa11932b08https://support.apple.com/HT204659http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2014-09/msg00046.htmlhttp://marc.info/?l=bugtraq&m=141017844705317&w=2http://mx.gw.com/pipermail/file/2014/001553.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1327.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1765.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1766.htmlhttp://secunia.com/advisories/59794http://secunia.com/advisories/59831http://support.apple.com/kb/HT6443http://www.debian.org/security/2014/dsa-2974http://www.debian.org/security/2014/dsa-3021http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.php.net/ChangeLog-5.phphttp://www.securityfocus.com/bid/68239https://bugs.php.net/bug.php?id=67410https://github.com/file/file/commit/27a14bc7ba285a0a5ebfdb55e54001aa11932b08https://support.apple.com/HT204659
2014-07-09
Published