Wind River Support Network

HomeDefectsLIN6-8878
Fixed

LIN6-8878 : Security Advisory - php - CVE-2014-3710

Created: Dec 1, 2014    Updated: Dec 3, 2018
Resolved Date: Dec 2, 2014
Found In Version: 6.0.0.15
Fix Version: 6.0.0.15
Severity: Standard
Applicable for: Wind River Linux 6
Component/s: Userspace

Description

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3710

Other Downloads


Live chat
Online