CVE-2014-3710
published 2014-11-05CVE-2014-3710: The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are…
PriorityP426medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
14.01%
96.1th percentile
The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | os_x_yosemite_v10.10.3_and_security_update_2015-004 | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | file | < file 1:5.20-2 (bookworm) | file 1:5.20-2 (bookworm) |
| file_project | file | >= 0 < 1:5.20-2 | 1:5.20-2 |
| file_project | file | >= 0 < 1:5.20-2 | 1:5.20-2 |
| file_project | file | >= 0 < 1:5.20-2 | 1:5.20-2 |
| file_project | file | >= 0 < 1:5.20-2 | 1:5.20-2 |
| file_project | file | >= 0 < 1:5.14-2ubuntu3.3 | 1:5.14-2ubuntu3.3 |
| php | php | >= 5.4.0 < 5.4.35 | 5.4.35 |
| php | php | >= 5.5.0 < 5.5.19 | 5.5.19 |
| php | php | >= 5.6.0 < 5.6.3 | 5.6.3 |
| php5 | php5 | >= 0 < 5.5.9+dfsg-1ubuntu4.5 | 5.5.9+dfsg-1ubuntu4.5 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3rf4-9569-4jw7: The donote function in readelf
ghsa_unreviewed·2022-05-14
CVE-2014-3710 [MEDIUM] CWE-20 GHSA-3rf4-9569-4jw7: The donote function in readelf
The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.
OSV
file vulnerabilities
osv·2015-02-04·CVSS 5.0
CVE-2014-3710 [MEDIUM] file vulnerabilities
file vulnerabilities
Francisco Alonso discovered that file incorrectly handled certain ELF
files. An attacker could use this issue to cause file to crash, resulting
in a denial of service. (CVE-2014-3710)
Thomas Jarosch discovered that file incorrectly handled certain ELF files.
An attacker could use this issue to cause file to hang or crash, resulting
in a denial of service. (CVE-2014-8116)
Thomas Jarosch discovered that file incorrectly limited recursion. An
attacker could use this issue to cause file to hang or crash, resulting in
a denial of service. (CVE-2014-8117)
OSV
CVE-2014-3710: The donote function in readelf
osv·2014-11-05·CVSS 5.0
CVE-2014-3710 [MEDIUM] CVE-2014-3710: The donote function in readelf
The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.
OSV
php5 vulnerabilities
osv·2014-10-30·CVSS 5.0
CVE-2014-3668 [MEDIUM] php5 vulnerabilities
php5 vulnerabilities
Symeon Paraschoudis discovered that PHP incorrectly handled the mkgmtime
function. A remote attacker could possibly use this issue to cause PHP to
crash, resulting in a denial of service. (CVE-2014-3668)
Symeon Paraschoudis discovered that PHP incorrectly handled unserializing
objects. A remote attacker could possibly use this issue to cause PHP to
crash, resulting in a denial of service. (CVE-2014-3669)
Otto Ebeling discovered that PHP incorrectly handled the exif_thumbnail
function. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2014-3670)
Francisco Alonso that PHP incorrectly handled ELF files in the fileinfo
extension. A remote attacker could possibly use this issue to cau
Ubuntu
file vulnerabilities
vendor_ubuntu·2015-02-04·CVSS 5.0
CVE-2014-3710 [MEDIUM] file vulnerabilities
Title: file vulnerabilities
Summary: file could be made to crash if it opened a specially crafted file.
Francisco Alonso discovered that file incorrectly handled certain ELF
files. An attacker could use this issue to cause file to crash, resulting
in a denial of service. (CVE-2014-3710)
Thomas Jarosch discovered that file incorrectly handled certain ELF files.
An attacker could use this issue to cause file to hang or crash, resulting
in a denial of service. (CVE-2014-8116)
Thomas Jarosch discovered that file incorrectly limited recursion. An
attacker could use this issue to cause file to hang or crash, resulting in
a denial of service. (CVE-2014-8117)
Instructions: In general, a standard system update will make all the necessary changes.
BSD
FreeBSD-SA-14:28.file: Multiple vulnerabilities in file(1) and libmagic(3)
bsd_advisories·2014-12-10·CVSS 5.0
CVE-2014-3710 [MEDIUM] FreeBSD-SA-14:28.file: Multiple vulnerabilities in file(1) and libmagic(3)
FreeBSD-SA-14:28.file Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities in file(1) and libmagic(3)
Category: contrib
Module: file
Announced: 2014-12-10
Affects: All supported versions of FreeBSD.
Credits: Thomas Jarosch of Intra2net AG
Corrected: 2014-12-10 08:26:53 UTC (stable/10, 10.1-STABLE)
2014-12-10 08:35:55 UTC (releng/10.1, 10.1-RELEASE-p1)
2014-12-10 08:36:07 UTC (releng/10.0, 10.0-RELEASE-p13)
2014-12-10 08:31:41 UTC (stable/9, 9.3-STABLE)
2014-12-10 08:36:40 UTC (releng/9.3, 9.3-RELEASE-p6)
2014-12-10 08:36:40 UTC (releng/9.2, 9.2-RELEASE-p16)
2014-12-10 08:36:40 UTC (releng/9.1, 9.1-RELEASE-p23)
2014-12-10 08:31:41 UTC (stable/8, 8.4-STABLE)
2014-12-10 08:36:40 UTC (releng/8.4, 8.4-RELEASE-p20)
CVE Name: CVE-2014-3710, CVE-2014-8116, CVE-2014-8117
For gen
Ubuntu
php5 vulnerabilities
vendor_ubuntu·2014-10-30·CVSS 5.0
CVE-2014-3668 [MEDIUM] php5 vulnerabilities
Title: php5 vulnerabilities
Summary: Several security issues were fixed in PHP.
Symeon Paraschoudis discovered that PHP incorrectly handled the mkgmtime
function. A remote attacker could possibly use this issue to cause PHP to
crash, resulting in a denial of service. (CVE-2014-3668)
Symeon Paraschoudis discovered that PHP incorrectly handled unserializing
objects. A remote attacker could possibly use this issue to cause PHP to
crash, resulting in a denial of service. (CVE-2014-3669)
Otto Ebeling discovered that PHP incorrectly handled the exif_thumbnail
function. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2014-3670)
Francisco Alonso that PHP incorrectly handled ELF files in the fileinfo
exten
Red Hat
file: out-of-bounds read in elf note headers
vendor_redhat·2014-10-22·CVSS 5.0
CVE-2014-3710 [MEDIUM] CWE-125 file: out-of-bounds read in elf note headers
file: out-of-bounds read in elf note headers
The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.
An out-of-bounds read flaw was found in the way the File Information (fileinfo) extension parsed Executable and Linkable Format (ELF) files. A remote attacker could use this flaw to crash a PHP application using fileinfo via a specially crafted ELF file.
Package: file (Red Hat Enterprise Linux 5) - Will not fix
Package: php (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2014-3710: file - The donote function in readelf.c in file through 5.20, as used in the Fileinfo c...
vendor_debian·2014·CVSS 5.0
CVE-2014-3710 [MEDIUM] CVE-2014-3710: file - The donote function in readelf.c in file through 5.20, as used in the Fileinfo c...
The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.
Scope: local
bookworm: resolved (fixed in 1:5.20-2)
bullseye: resolved (fixed in 1:5.20-2)
forky: resolved (fixed in 1:5.20-2)
sid: resolved (fixed in 1:5.20-2)
trixie: resolved (fixed in 1:5.20-2)
Apple
CVE-2014-3710: OS X Yosemite v10.10.3 and Security Update 2015-004
vendor_apple·CVSS 5.0
CVE-2014-3710 [MEDIUM] CVE-2014-3710: OS X Yosemite v10.10.3 and Security Update 2015-004
Apple Security Update: About the security content of OS X Yosemite v10.10.3 and Security Update 2015-004
Product: OS X Yosemite v10.10.3 and Security Update 2015-004
CVE: CVE-2014-3710
Component: CVE-2014-3710
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3710 file: out-of-bounds read in elf note headers [fedora-all]
bugzilla·2014-10-22·CVSS 5.0
CVE-2014-3710 [MEDIUM] CVE-2014-3710 file: out-of-bounds read in elf note headers [fedora-all]
CVE-2014-3710 file: out-of-bounds read in elf note headers [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora
Bugzilla
CVE-2014-3710 php: file: out-of-bounds read in elf note headers [fedora-all]
bugzilla·2014-10-22·CVSS 5.0
CVE-2014-3710 [MEDIUM] CVE-2014-3710 php: file: out-of-bounds read in elf note headers [fedora-all]
CVE-2014-3710 php: file: out-of-bounds read in elf note headers [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of F
Bugzilla
CVE-2014-3710 file: out-of-bounds read in elf note headers
bugzilla·2014-10-21·CVSS 5.0
CVE-2014-3710 [MEDIUM] CVE-2014-3710 file: out-of-bounds read in elf note headers
CVE-2014-3710 file: out-of-bounds read in elf note headers
An out-of-bounds read flaw was found in file's donote() function in the way the file utility determined the note headers of a elf file. This could possibly lead to file executable crash.
Upstream fix:
https://github.com/file/file/commit/39c7ac1106be844a5296d3eb5971946cc09ffda0
Discussion:
Created php tracking bugs for this issue:
Affects: fedora-all [bug 1155465]
---
Created file tracking bugs for this issue:
Affects: fedora-all [bug 1155464]
---
PHP upstream bug:
https://bugs.php.net/bug.php?id=68283
PHP upstream commit (PHP 5.4 branch for now):
http://git.php.net/?p=php-src.git;a=commitdiff;h=1803228
---
file-5.19-7.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make not
http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=1803228597e82218a8c105e67975bc50e6f5bf0dhttp://linux.oracle.com/errata/ELSA-2014-1767.htmlhttp://linux.oracle.com/errata/ELSA-2014-1768.htmlhttp://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00113.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1765.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1766.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1767.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1768.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0760.htmlhttp://secunia.com/advisories/60630http://secunia.com/advisories/60699http://secunia.com/advisories/61763http://secunia.com/advisories/61970http://secunia.com/advisories/61982http://secunia.com/advisories/62347http://secunia.com/advisories/62559http://www.debian.org/security/2014/dsa-3072http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/70807http://www.securitytracker.com/id/1031344http://www.ubuntu.com/usn/USN-2391-1http://www.ubuntu.com/usn/USN-2494-1https://bugs.php.net/bug.php?id=68283https://bugzilla.redhat.com/show_bug.cgi?id=1155071https://github.com/file/file/commit/39c7ac1106be844a5296d3eb5971946cc09ffda0https://security.gentoo.org/glsa/201503-03https://security.gentoo.org/glsa/201701-42https://support.apple.com/HT204659https://www.freebsd.org/security/advisories/FreeBSD-SA-14:28.file.aschttp://git.php.net/?p=php-src.git%3Ba=commit%3Bh=1803228597e82218a8c105e67975bc50e6f5bf0dhttp://linux.oracle.com/errata/ELSA-2014-1767.htmlhttp://linux.oracle.com/errata/ELSA-2014-1768.htmlhttp://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00113.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1765.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1766.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1767.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1768.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0760.htmlhttp://secunia.com/advisories/60630http://secunia.com/advisories/60699http://secunia.com/advisories/61763http://secunia.com/advisories/61970http://secunia.com/advisories/61982http://secunia.com/advisories/62347http://secunia.com/advisories/62559http://www.debian.org/security/2014/dsa-3072http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/70807http://www.securitytracker.com/id/1031344http://www.ubuntu.com/usn/USN-2391-1http://www.ubuntu.com/usn/USN-2494-1https://bugs.php.net/bug.php?id=68283https://bugzilla.redhat.com/show_bug.cgi?id=1155071https://github.com/file/file/commit/39c7ac1106be844a5296d3eb5971946cc09ffda0https://security.gentoo.org/glsa/201503-03https://security.gentoo.org/glsa/201701-42https://support.apple.com/HT204659https://www.freebsd.org/security/advisories/FreeBSD-SA-14:28.file.asc
2014-11-05
Published