CVE-2014-3587
published 2014-08-23CVE-2014-3587: Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before…
PriorityP427medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
20.24%
97.2th percentile
Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1571.
Affected
75 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | os_x_yosemite_v10.10.3_and_security_update_2015-004 | — | — |
| christos_zoulas | file | <= 5.19 | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| debian | file | < file 1:5.19-2 (bookworm) | file 1:5.19-2 (bookworm) |
| file_project | file | >= 0 < 1:5.19-2 | 1:5.19-2 |
| file_project | file | >= 0 < 1:5.19-2 | 1:5.19-2 |
| file_project | file | >= 0 < 1:5.19-2 | 1:5.19-2 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5mp5-8xxq-j3vx: Integer overflow in the cdf_read_property_info function in cdf
ghsa_unreviewed·2022-05-14·CVSS 6.5
CVE-2014-3587 [MEDIUM] GHSA-5mp5-8xxq-j3vx: Integer overflow in the cdf_read_property_info function in cdf
Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1571.
OSV
php5 vulnerabilities
osv·2014-09-10·CVSS 4.3
CVE-2014-3587 [MEDIUM] php5 vulnerabilities
php5 vulnerabilities
It was discovered that the Fileinfo component in php5 contains an integer
overflow. An attacker could use this flaw to cause a denial of service
or possibly execute arbitrary code via a crafted CDF file. (CVE-2014-3587)
It was discovered that the php_parserr function contains multiple buffer
overflows. An attacker could use this flaw to cause a denial of service
or possibly execute arbitrary code via crafted DNS records. (CVE-2014-3597)
OSV
CVE-2014-3587: Integer overflow in the cdf_read_property_info function in cdf
osv·2014-08-23·CVSS 6.5
CVE-2014-3587 [MEDIUM] CVE-2014-3587: Integer overflow in the cdf_read_property_info function in cdf
Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1571.
Ubuntu
file vulnerability
vendor_ubuntu·2014-10-03
CVE-2014-3587 file vulnerability
Title: file vulnerability
Summary: file could be made to crash or run programs as your login if it
opened a specially crafted file.
It was discovered that file incorrectly handled certain CDF documents. A
attacker could use this issue to cause file to hang or crash, resulting
in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2014-09-10·CVSS 4.3
CVE-2014-3587 [MEDIUM] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: php5 could be made to crash or run programs if it received
specially crafted network traffic.
It was discovered that the Fileinfo component in php5 contains an integer
overflow. An attacker could use this flaw to cause a denial of service
or possibly execute arbitrary code via a crafted CDF file. (CVE-2014-3587)
It was discovered that the php_parserr function contains multiple buffer
overflows. An attacker could use this flaw to cause a denial of service
or possibly execute arbitrary code via crafted DNS records. (CVE-2014-3597)
Instructions: After a standard system update you need to restart Apache or
php5-fpm to make all the necessary changes.
Red Hat
file: incomplete fix for CVE-2012-1571 in cdf_read_property_info
vendor_redhat·2014-08-21·CVSS 6.5
CVE-2014-3587 [MEDIUM] CWE-190 file: incomplete fix for CVE-2012-1571 in cdf_read_property_info
file: incomplete fix for CVE-2012-1571 in cdf_read_property_info
Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1571.
It was found that the fix for CVE-2012-1571 was incomplete; the File Information (fileinfo) extension did not correctly parse certain Composite Document Format (CDF) files. A remote attacker could use this flaw to crash a PHP application using fileinfo via a specially crafted CDF file.
Statement: This issue did not affect the php and the file packages as shipped with Red Hat Enterprise
Debian
CVE-2014-3587: file - Integer overflow in the cdf_read_property_info function in cdf.c in file through...
vendor_debian·2014·CVSS 6.5
CVE-2014-3587 [MEDIUM] CVE-2014-3587: file - Integer overflow in the cdf_read_property_info function in cdf.c in file through...
Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1571.
Scope: local
bookworm: resolved (fixed in 1:5.19-2)
bullseye: resolved (fixed in 1:5.19-2)
forky: resolved (fixed in 1:5.19-2)
sid: resolved (fixed in 1:5.19-2)
trixie: resolved (fixed in 1:5.19-2)
Apple
CVE-2014-3587: OS X Yosemite v10.10.3 and Security Update 2015-004
vendor_apple·CVSS 4.3
CVE-2014-3587 [MEDIUM] CVE-2014-3587: OS X Yosemite v10.10.3 and Security Update 2015-004
Apple Security Update: About the security content of OS X Yosemite v10.10.3 and Security Update 2015-004
Product: OS X Yosemite v10.10.3 and Security Update 2015-004
CVE: CVE-2014-3587
Component: CVE-2014-3587
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3587 php: file: incomplete fix for CVE-2012-1571 in cdf_read_property_info [fedora-all]
bugzilla·2014-08-22·CVSS 6.5
CVE-2014-3587 [MEDIUM] CVE-2014-3587 php: file: incomplete fix for CVE-2012-1571 in cdf_read_property_info [fedora-all]
CVE-2014-3587 php: file: incomplete fix for CVE-2012-1571 in cdf_read_property_info [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple sup
Bugzilla
CVE-2014-3587 file: incomplete fix for CVE-2012-1571 in cdf_read_property_info [fedora-all]
bugzilla·2014-08-22·CVSS 6.5
CVE-2014-3587 [MEDIUM] CVE-2014-3587 file: incomplete fix for CVE-2012-1571 in cdf_read_property_info [fedora-all]
CVE-2014-3587 file: incomplete fix for CVE-2012-1571 in cdf_read_property_info [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
Bugzilla
CVE-2014-3587 file: incomplete fix for CVE-2012-1571 in cdf_read_property_info
bugzilla·2014-08-11·CVSS 6.5
CVE-2014-3587 [MEDIUM] CVE-2014-3587 file: incomplete fix for CVE-2012-1571 in cdf_read_property_info
CVE-2014-3587 file: incomplete fix for CVE-2012-1571 in cdf_read_property_info
A flaw was found in the way file uses cdf_read_property_info function when checks stream offsets for certain Composite Document Format (CDF).An insufficient input validation flaw for p and q minimal and maximal value, leads to a pointer overflow.This issue only affects 32bit systems.
771 cdf_read_property_info(const cdf_stream_t *sst, const cdf_header_t *h
..
835 q = (const uint8_t *)(const void *)
836 ((const char *)(const void *)p + ofs
837 - 2 * sizeof(uint32_t));
838 if (q > e) {
839 DPRINTF(("Ran of the end %p > %p\n", q, e));
840 goto out;
841 }
Upstream commit:
https://github.com/file/file/commit/0641e56be1af003aa02c7c6b0184466540637233
Discussion:
This issue is public:
http://lwn.net/Vulnerabilitie
http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlhttp://php.net/ChangeLog-5.phphttp://rhn.redhat.com/errata/RHSA-2014-1326.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1327.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1765.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1766.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0760.htmlhttp://secunia.com/advisories/60609http://secunia.com/advisories/60696http://www.debian.org/security/2014/dsa-3008http://www.debian.org/security/2014/dsa-3021http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/69325http://www.ubuntu.com/usn/USN-2344-1http://www.ubuntu.com/usn/USN-2369-1https://bugs.php.net/bug.php?id=67716https://github.com/file/file/commit/0641e56be1af003aa02c7c6b0184466540637233https://github.com/php/php-src/commit/7ba1409a1aee5925180de546057ddd84ff267947https://security-tracker.debian.org/tracker/CVE-2014-3587https://support.apple.com/HT204659http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlhttp://php.net/ChangeLog-5.phphttp://rhn.redhat.com/errata/RHSA-2014-1326.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1327.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1765.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1766.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0760.htmlhttp://secunia.com/advisories/60609http://secunia.com/advisories/60696http://www.debian.org/security/2014/dsa-3008http://www.debian.org/security/2014/dsa-3021http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/69325http://www.ubuntu.com/usn/USN-2344-1http://www.ubuntu.com/usn/USN-2369-1https://bugs.php.net/bug.php?id=67716https://github.com/file/file/commit/0641e56be1af003aa02c7c6b0184466540637233https://github.com/php/php-src/commit/7ba1409a1aee5925180de546057ddd84ff267947https://security-tracker.debian.org/tracker/CVE-2014-3587https://support.apple.com/HT204659
2014-08-23
Published