CVE-2014-9652
published 2015-03-30CVE-2014-9652: The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5…
PriorityP425medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
5.45%
91.8th percentile
The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | os_x_el_capitan_v10.11 | — | — |
| debian | file | < file 1:5.21+15-1 (bookworm) | file 1:5.21+15-1 (bookworm) |
| file_project | file | <= 5.20 | — |
| file_project | file | >= 0 < 1:5.21+15-1 | 1:5.21+15-1 |
| file_project | file | >= 0 < 1:5.21+15-1 | 1:5.21+15-1 |
| file_project | file | >= 0 < 1:5.21+15-1 | 1:5.21+15-1 |
| file_project | file | >= 0 < 1:5.21+15-1 | 1:5.21+15-1 |
| php | php | <= 5.4.36 | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4mj2-cv5h-vvmg: The mconvert function in softmagic
ghsa_unreviewed·2022-05-17
CVE-2014-9652 [MEDIUM] CWE-119 GHSA-4mj2-cv5h-vvmg: The mconvert function in softmagic
The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file.
OSV
CVE-2014-9652: The mconvert function in softmagic
osv·2015-03-30·CVSS 5.0
CVE-2014-9652 [MEDIUM] CVE-2014-9652: The mconvert function in softmagic
The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file.
OSV
php5 vulnerabilities
osv·2015-02-17·CVSS 7.5
CVE-2014-8142 [HIGH] php5 vulnerabilities
php5 vulnerabilities
Stefan Esser discovered that PHP incorrectly handled unserializing objects.
A remote attacker could use this issue to cause PHP to crash, resulting in
a denial of service, or possibly execute arbitrary code. (CVE-2014-8142,
CVE-2015-0231)
Brian Carpenter discovered that the PHP CGI component incorrectly handled
invalid files. A local attacker could use this issue to obtain sensitive
information, or possibly execute arbitrary code. This issue only affected
Ubuntu 14.04 LTS and Ubuntu 14.10. (CVE-2014-9427)
It was discovered that PHP incorrectly handled certain pascal strings in
the fileinfo extension. A remote attacker could possibly use this issue to
cause PHP to crash, resulting in a denial of service. This issue only
affected Ubuntu 14.04 LTS and Ubuntu 14.10. (CV
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2015-02-17·CVSS 7.5
CVE-2014-8142 [HIGH] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
Stefan Esser discovered that PHP incorrectly handled unserializing objects.
A remote attacker could use this issue to cause PHP to crash, resulting in
a denial of service, or possibly execute arbitrary code. (CVE-2014-8142,
CVE-2015-0231)
Brian Carpenter discovered that the PHP CGI component incorrectly handled
invalid files. A local attacker could use this issue to obtain sensitive
information, or possibly execute arbitrary code. This issue only affected
Ubuntu 14.04 LTS and Ubuntu 14.10. (CVE-2014-9427)
It was discovered that PHP incorrectly handled certain pascal strings in
the fileinfo extension. A remote attacker could possibly use this issue to
cause PHP to crash, resulting in a denial of service. This
Red Hat
file: out of bounds read in mconvert()
vendor_redhat·2014-11-11·CVSS 5.0
CVE-2014-9652 [MEDIUM] CWE-125 file: out of bounds read in mconvert()
file: out of bounds read in mconvert()
The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file.
An ouf-of-bounds read flaw was found in the way the file utility processed certain Pascal strings. A remote attacker could cause an application using the file utility (for example, PHP using the fileinfo module) to crash if it was used to identify the type of the attacker-supplied file.
Package: cdrtools (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2014-9652: file - The mconvert function in softmagic.c in file before 5.21, as used in the Fileinf...
vendor_debian·2014·CVSS 5.0
CVE-2014-9652 [MEDIUM] CVE-2014-9652: file - The mconvert function in softmagic.c in file before 5.21, as used in the Fileinf...
The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file.
Scope: local
bookworm: resolved (fixed in 1:5.21+15-1)
bullseye: resolved (fixed in 1:5.21+15-1)
forky: resolved (fixed in 1:5.21+15-1)
sid: resolved (fixed in 1:5.21+15-1)
trixie: resolved (fixed in 1:5.21+15-1)
Apple
CVE-2014-9652: OS X El Capitan v10.11
vendor_apple·CVSS 5.0
CVE-2014-9652 [MEDIUM] CVE-2014-9652: OS X El Capitan v10.11
Apple Security Update: About the security content of OS X El Capitan v10.11
Product: OS X El Capitan v10.11
CVE: CVE-2014-9652
Component: CVE-2014-9652
No detection rules found.
No public exploits indexed.
HackerOne
PHP 5.4.45 is Outdated and Full of Preformance Interupting Arbitrary Code Execution Bugs
hackerone·2017-08-21·CVSS 3.3
CVE-2015-2301 [LOW] PHP 5.4.45 is Outdated and Full of Preformance Interupting Arbitrary Code Execution Bugs
PHP 5.4.45 is Outdated and Full of Preformance Interupting Arbitrary Code Execution Bugs
Your PHP version is affected by quite a few remote arbitrary code execution, remote file renaming, and remote file rewriting bugs that require no authentication and can cause big problems, from performance interruptions and messing with server files to DoS attacks. These are not related to any particular non-default module, but php itself.
Here's a little list I compiled:
CVE-2015-2301
CVE-2014-9652
CVE-2014-5459
CVE-2014-4698
CVE-2014-4670
CVE-2014-3981
Bugzilla
CVE-2014-9652 file: out of bounds read in mconvert()
bugzilla·2015-02-03·CVSS 5.0
CVE-2014-9652 [MEDIUM] CVE-2014-9652 file: out of bounds read in mconvert()
CVE-2014-9652 file: out of bounds read in mconvert()
Out of bounds memory read was reported in file utility [1], which also affects PHP fileinfo module.
Upstream fix that resolves this for file utility:
https://github.com/file/file/commit/59e63838913eee47f5c120a6c53d4565af638158
PHP upstream fix:
https://github.com/php/php-src/commit/ede59c8feb4b80e1b94e4abdaa0711051e2912ab
[1]: http://bugs.gw.com/view.php?id=398
Discussion:
Fixed upstream in PHP 5.6.5, 5.5.21 and 5.4.37:
http://php.net/ChangeLog-5.php#5.6.5
http://php.net/ChangeLog-5.php#5.5.21
http://php.net/ChangeLog-5.php#5.4.37
---
Fixed upstream in file 5.21:
http://bugs.gw.com/changelog_page.php?version_id=36
---
This issue has been addressed in the following products:
Red Hat Software Collections for Red Hat Enterprise
http://bugs.gw.com/view.php?id=398http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00004.htmlhttp://marc.info/?l=bugtraq&m=143748090628601&w=2http://marc.info/?l=bugtraq&m=144050155601375&w=2http://openwall.com/lists/oss-security/2015/02/05/12http://php.net/ChangeLog-5.phphttp://rhn.redhat.com/errata/RHSA-2015-1053.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1066.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1135.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/72505https://bugs.php.net/bug.php?id=68735https://bugs.php.net/patch-display.php?bug=68735&patch=bug68735.patch&revision=1420309079https://github.com/file/file/commit/59e63838913eee47f5c120a6c53d4565af638158https://security.gentoo.org/glsa/201701-42https://support.apple.com/HT205267http://bugs.gw.com/view.php?id=398http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00004.htmlhttp://marc.info/?l=bugtraq&m=143748090628601&w=2http://marc.info/?l=bugtraq&m=144050155601375&w=2http://openwall.com/lists/oss-security/2015/02/05/12http://php.net/ChangeLog-5.phphttp://rhn.redhat.com/errata/RHSA-2015-1053.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1066.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1135.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/72505https://bugs.php.net/bug.php?id=68735https://bugs.php.net/patch-display.php?bug=68735&patch=bug68735.patch&revision=1420309079https://github.com/file/file/commit/59e63838913eee47f5c120a6c53d4565af638158https://security.gentoo.org/glsa/201701-42https://support.apple.com/HT205267
2015-03-30
Published