← All CVEs

CVE-2014-0238

medium · 5

The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (infinite loop or out-of-bounds memory access) via a vector that (1) has zero length or (2) is too long.

5
CVSS
20.8%
EPSS (exploit prob.)
97th
EPSS percentile
2014-06-01
Published

AV:N/AC:L/Au:N/C:N/I:N/A:P

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
phpphp< 5.3.29
phpphp>= 5.4.0, < 5.4.29
phpphp>= 5.5.0, < 5.5.13
debiandebian_linux7.0
debiandebian_linux8.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-0238