Wind River Support Network

HomeDefectsLIN5-19802
Fixed

LIN5-19802 : Security Advisory - php - CVE-2014-3710

Created: Dec 1, 2014    Updated: Dec 19, 2017
Resolved Date: Dec 2, 2014
Found In Version: 5.0.1.22
Fix Version: 5.0.1.22
Severity: Standard
Applicable for: Wind River Linux 5
Component/s: Userspace

Description

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3710

Other Downloads


Live chat
Online