CVE-2014-3479
published 2014-07-09CVE-2014-3479: The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on…
PriorityP423medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
14.93%
96.3th percentile
The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to cause a denial of service (application crash) via a crafted stream offset in a CDF file.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | os_x_yosemite_v10.10.3_and_security_update_2015-004 | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | file | < file 1:5.19-1 (bookworm) | file 1:5.19-1 (bookworm) |
| file_project | file | < 5.19 | 5.19 |
| file_project | file | >= 0 < 1:5.19-1 | 1:5.19-1 |
| file_project | file | >= 0 < 1:5.19-1 | 1:5.19-1 |
| file_project | file | >= 0 < 1:5.19-1 | 1:5.19-1 |
| file_project | file | >= 0 < 1:5.19-1 | 1:5.19-1 |
| file_project | file | >= 0 < 1:5.14-2ubuntu3.1 | 1:5.14-2ubuntu3.1 |
| opensuse | opensuse | — | — |
| oracle | linux | — | — |
| php | php | < 5.3.29 | 5.3.29 |
| php | php | >= 5.4.0 < 5.4.30 | 5.4.30 |
| php | php | >= 5.5.0 < 5.5.14 | 5.5.14 |
| php5 | php5 | >= 0 < 5.5.9+dfsg-1ubuntu4.3 | 5.5.9+dfsg-1ubuntu4.3 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
file vulnerabilities
vendor_ubuntu·2014-07-15·CVSS 5.0
CVE-2013-7345 [MEDIUM] file vulnerabilities
Title: file vulnerabilities
Summary: File could be made to crash or hang if it processed specially crafted data.
Mike Frysinger discovered that the file awk script detector used multiple
wildcard with unlimited repetitions. An attacker could use this issue to
cause file to consume resources, resulting in a denial of service.
(CVE-2013-7345)
Francisco Alonso discovered that file incorrectly handled certain CDF
documents. A attacker could use this issue to cause file to hang or crash,
resulting in a denial of service. (CVE-2014-0207, CVE-2014-3478,
CVE-2014-3479, CVE-2014-3480, CVE-2014-3487)
Jan Kaluža discovered that file did not properly restrict the amount of
data read during regex searches. An attacker could use this issue to
cause file to consume resources, resulting in a denial of
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2014-07-09·CVSS 6.5
CVE-2014-0207 [MEDIUM] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
Francisco Alonso discovered that the PHP Fileinfo component incorrectly
handled certain CDF documents. A remote attacker could use this issue to
cause PHP to hang or crash, resulting in a denial of service.
(CVE-2014-0207, CVE-2014-3478, CVE-2014-3479, CVE-2014-3480, CVE-2014-3487)
Stefan Esser discovered that PHP incorrectly handled unserializing SPL
extension objects. An attacker could use this issue to execute arbitrary
code. (CVE-2014-3515)
It was discovered that PHP incorrectly handled certain SPL Iterators. An
attacker could use this issue to cause PHP to crash, resulting in a denial
of service. (CVE-2014-4670)
It was discovered that PHP incorrectly handled certain ArrayIterators. An
attacker could us
Red Hat
file: cdf_check_stream_offset insufficient boundary check
vendor_redhat·2014-06-27·CVSS 4.3
CVE-2014-3479 [MEDIUM] file: cdf_check_stream_offset insufficient boundary check
file: cdf_check_stream_offset insufficient boundary check
The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to cause a denial of service (application crash) via a crafted stream offset in a CDF file.
A denial of service flaw was found in the way the File Information (fileinfo) extension parsed certain Composite Document Format (CDF) files. A remote attacker could use this flaw to crash a PHP application using fileinfo via a specially crafted CDF file.
Statement: This issue did not affect the php and the file packages as shipped with Red Hat Enterprise Linux 5.
This issue affects the versions of file as shipped with Red Hat E
Debian
CVE-2014-3479: file - The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in th...
vendor_debian·2014·CVSS 4.3
CVE-2014-3479 [MEDIUM] CVE-2014-3479: file - The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in th...
The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to cause a denial of service (application crash) via a crafted stream offset in a CDF file.
Scope: local
bookworm: resolved (fixed in 1:5.19-1)
bullseye: resolved (fixed in 1:5.19-1)
forky: resolved (fixed in 1:5.19-1)
sid: resolved (fixed in 1:5.19-1)
trixie: resolved (fixed in 1:5.19-1)
Apple
CVE-2014-3479: OS X Yosemite v10.10.3 and Security Update 2015-004
vendor_apple·CVSS 4.3
CVE-2014-3479 [MEDIUM] CVE-2014-3479: OS X Yosemite v10.10.3 and Security Update 2015-004
Apple Security Update: About the security content of OS X Yosemite v10.10.3 and Security Update 2015-004
Product: OS X Yosemite v10.10.3 and Security Update 2015-004
CVE: CVE-2014-3479
Component: CVE-2014-3479
GHSA
GHSA-6wwp-p7c5-p9pm: The cdf_check_stream_offset function in cdf
ghsa_unreviewed·2022-05-17
CVE-2014-3479 [MEDIUM] GHSA-6wwp-p7c5-p9pm: The cdf_check_stream_offset function in cdf
The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to cause a denial of service (application crash) via a crafted stream offset in a CDF file.
OSV
file vulnerabilities
osv·2014-07-15·CVSS 5.0
CVE-2013-7345 [MEDIUM] file vulnerabilities
file vulnerabilities
Mike Frysinger discovered that the file awk script detector used multiple
wildcard with unlimited repetitions. An attacker could use this issue to
cause file to consume resources, resulting in a denial of service.
(CVE-2013-7345)
Francisco Alonso discovered that file incorrectly handled certain CDF
documents. A attacker could use this issue to cause file to hang or crash,
resulting in a denial of service. (CVE-2014-0207, CVE-2014-3478,
CVE-2014-3479, CVE-2014-3480, CVE-2014-3487)
Jan Kaluža discovered that file did not properly restrict the amount of
data read during regex searches. An attacker could use this issue to
cause file to consume resources, resulting in a denial of service.
(CVE-2014-3538)
OSV
CVE-2014-3479: The cdf_check_stream_offset function in cdf
osv·2014-07-09·CVSS 4.3
CVE-2014-3479 [MEDIUM] CVE-2014-3479: The cdf_check_stream_offset function in cdf
The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to cause a denial of service (application crash) via a crafted stream offset in a CDF file.
OSV
php5 vulnerabilities
osv·2014-07-09·CVSS 6.5
CVE-2014-0207 [MEDIUM] php5 vulnerabilities
php5 vulnerabilities
Francisco Alonso discovered that the PHP Fileinfo component incorrectly
handled certain CDF documents. A remote attacker could use this issue to
cause PHP to hang or crash, resulting in a denial of service.
(CVE-2014-0207, CVE-2014-3478, CVE-2014-3479, CVE-2014-3480, CVE-2014-3487)
Stefan Esser discovered that PHP incorrectly handled unserializing SPL
extension objects. An attacker could use this issue to execute arbitrary
code. (CVE-2014-3515)
It was discovered that PHP incorrectly handled certain SPL Iterators. An
attacker could use this issue to cause PHP to crash, resulting in a denial
of service. (CVE-2014-4670)
It was discovered that PHP incorrectly handled certain ArrayIterators. An
attacker could use this issue to cause PHP to crash, resulting in a denial
o
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3479 file: cdf_check_stream_offset insufficient boundary check [fedora-all]
bugzilla·2014-06-30·CVSS 4.3
CVE-2014-3479 [MEDIUM] CVE-2014-3479 file: cdf_check_stream_offset insufficient boundary check [fedora-all]
CVE-2014-3479 file: cdf_check_stream_offset insufficient boundary check [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects mu
Bugzilla
CVE-2014-3479 php: file: cdf_check_stream_offset insufficient boundary check [fedora-all]
bugzilla·2014-06-30·CVSS 4.3
CVE-2014-3479 [MEDIUM] CVE-2014-3479 php: file: cdf_check_stream_offset insufficient boundary check [fedora-all]
CVE-2014-3479 php: file: cdf_check_stream_offset insufficient boundary check [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affec
Bugzilla
CVE-2014-3479 file: cdf_check_stream_offset insufficient boundary check
bugzilla·2014-06-04·CVSS 4.3
CVE-2014-3479 [MEDIUM] CVE-2014-3479 file: cdf_check_stream_offset insufficient boundary check
CVE-2014-3479 file: cdf_check_stream_offset insufficient boundary check
A flaw was found in the way file uses cdf_check_stream_offset function when checks stream offsets for certain Composite Document Format (CDF).
Upstream commit:
https://github.com/file/file/commit/36fadd29849b8087af9f4586f89dbf74ea45be67
Acknowledgements:
This issue was discovered by Francisco Alonso of Red Hat Product Security.
Discussion:
PHP commit:
http://git.php.net/?p=php-src.git;a=commit;h=5c9f96799961818944d43b22c241cc56c215c2e4
---
Created php tracking bugs for this issue:
Affects: fedora-all [bug 1114452]
---
Created file tracking bugs for this issue:
Affects: fedora-all [bug 1114451]
---
file-5.19-1.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make
Tenable
[R6] SecurityCenter Affected by Multiple Third-party Library Vulnerabilities
blogs_tenable·2014-07-16
[R6] SecurityCenter Affected by Multiple Third-party Library Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2014-09/msg00046.htmlhttp://marc.info/?l=bugtraq&m=141017844705317&w=2http://mx.gw.com/pipermail/file/2014/001553.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1765.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1766.htmlhttp://secunia.com/advisories/59794http://secunia.com/advisories/59831http://support.apple.com/kb/HT6443http://www.debian.org/security/2014/dsa-2974http://www.debian.org/security/2014/dsa-3021http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.php.net/ChangeLog-5.phphttp://www.securityfocus.com/bid/68241https://bugs.php.net/bug.php?id=67411https://github.com/file/file/commit/36fadd29849b8087af9f4586f89dbf74ea45be67https://support.apple.com/HT204659http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2014-09/msg00046.htmlhttp://marc.info/?l=bugtraq&m=141017844705317&w=2http://mx.gw.com/pipermail/file/2014/001553.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1765.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1766.htmlhttp://secunia.com/advisories/59794http://secunia.com/advisories/59831http://support.apple.com/kb/HT6443http://www.debian.org/security/2014/dsa-2974http://www.debian.org/security/2014/dsa-3021http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.php.net/ChangeLog-5.phphttp://www.securityfocus.com/bid/68241https://bugs.php.net/bug.php?id=67411https://github.com/file/file/commit/36fadd29849b8087af9f4586f89dbf74ea45be67https://support.apple.com/HT204659
2014-07-09
Published