← All CVEs

CVE-2014-3710

medium · 5

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

5
CVSS
14.0%
EPSS (exploit prob.)
96th
EPSS percentile
2014-11-05
Published

AV:N/AC:L/Au:N/C:N/I:N/A:P

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
phpphp>= 5.4.0, < 5.4.35
phpphp>= 5.5.0, < 5.5.19
phpphp>= 5.6.0, < 5.6.3
debiandebian_linux7.0
debiandebian_linux8.0
canonicalubuntu_linux10.04
canonicalubuntu_linux12.04
canonicalubuntu_linux14.04
canonicalubuntu_linux14.10

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-3710