CVE-2014-3478

Published Jul 9, 2014

Last updated 2 months ago

Overview

Description
Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (application crash) via a crafted Pascal string in a FILE_PSTRING conversion.
Source
secalert@redhat.com
NVD status
Modified
Products
file, php

Risk scores

CVSS 3.1

Type
Secondary
Base score
6.5
Impact score
3.6
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Severity
MEDIUM

CVSS 2.0

Type
Primary
Base score
5
Impact score
2.9
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:N/I:N/A:P

Weaknesses

nvd@nist.gov
CWE-119
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-119

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.