← All CVEs

CVE-2014-9427

high · 7.5

sapi/cgi/cgi_main.c in the CGI component in PHP through 5.4.36, 5.5.x through 5.5.20, and 5.6.x through 5.6.4, when mmap is used to read a .php file, does not properly consider the mapping's length during processing of an invalid file that begins with a # character and lacks a newline character, which causes an out-of-bounds read and might (1) allow remote attackers to obtain sensitive information from php-cgi process memory by leveraging the ability to upload a .php file or (2) trigger unexpected code execution if a valid PHP script is present in memory locations adjacent to the mapping.

7.5
CVSS
18.3%
EPSS (exploit prob.)
97th
EPSS percentile
2015-01-03
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
phpphp1.0
phpphp2.0
phpphp2.0b10
phpphp3.0
phpphp3.0.1
phpphp3.0.2
phpphp3.0.3
phpphp3.0.4
phpphp3.0.5
phpphp3.0.6
phpphp3.0.7
phpphp3.0.8
phpphp3.0.9
phpphp3.0.10
phpphp3.0.11
phpphp3.0.12
phpphp3.0.13
phpphp3.0.14
phpphp3.0.15
phpphp3.0.16
phpphp3.0.17
phpphp3.0.18
phpphp4.0
phpphp4.0
phpphp4.0
phpphp4.0
phpphp4.0
phpphp4.0.0
phpphp4.0.1
phpphp4.0.2
phpphp4.0.3
phpphp4.0.4
phpphp4.0.5
phpphp4.0.6
phpphp4.0.7
phpphp4.1.0
phpphp4.1.1
phpphp4.1.2
phpphp4.2.0
phpphp4.2.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-9427