CVE-2014-3479

Advisory lineage Upstream: 0 Downstream: 17
Modified
Published: 09 Jul 2014, 10:00
Last modified:06 Aug 2024, 10:43

Vulnerability Summary

Overall Risk (default)
low
18/100
CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
5.92% LOW
6% probability -4.43%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 Jul 2014, 10:00
Published
Vulnerability first disclosed
06 Aug 2024, 10:43
Last Modified
Vulnerability information updated

Description

The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to cause a denial of service (application crash) via a crafted stream offset in a CDF file.

CVSS Metrics

  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 5.92% Percentile: 91%

Affected Systems

  • debiandebian_linux

    7.0 | 8.0

  • file_projectfile

    < 5.19

  • opensuseopensuse

    11.4

  • oraclelinux

    7

  • UnknownPHP

    < 5.3.29 | ≥ 5.4.0, < 5.4.30 | ≥ 5.5.0, < 5.5.14

References (18)