Wind River Support Network

HomeDefectsLIN6-12236
Fixed

LIN6-12236 : Security Advisory - php - CVE-2014-9912

Created: Jan 12, 2017    Updated: Dec 3, 2018
Resolved Date: Jan 15, 2017
Found In Version: 6.0.0.32
Fix Version: 6.0.0.33
Severity: Standard
Applicable for: Wind River Linux 6
Component/s: Userspace

Description

The get_icu_disp_value_src_php function in ext/intl/locale/locale_methods.c in PHP before 5.3.29, 5.4.x before 5.4.30, and 5.5.x before 5.5.14 does not properly restrict calls to the ICU uresbund.cpp component, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a locale_get_display_name call with a long first argument.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9912

Other Downloads


Live chat
Online