CVE-2014-3479 — Project File vulnerability
15 documents10 sources
Severity
4.3MEDIUMNVD
OSV6.5OSV5.0
EPSS
10.4%
top 6.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 9
Latest updateMay 17
Description
The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to cause a denial of service (application crash) via a crafted stream offset in a CDF file.
CVSS vector
AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9
Affected Packages7 packages
Also affects: Debian Linux 7.0, 8.0
Patches
🔴Vulnerability Details
5📋Vendor Advisories
5Debian▶
CVE-2014-3479: file - The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in th...↗2014
🕵️Threat Intelligence
1💬Community
3Bugzilla
▶
Bugzilla▶
CVE-2014-3479 php: file: cdf_check_stream_offset insufficient boundary check [fedora-all]↗2014-06-30