[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253928

 
 

909

 
 

198006

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2014-415 ---- php55

ID: oval:org.secpod.oval:def:1600129Date: (C)2016-01-19   (M)2023-12-07
Class: PATCHFamily: unix




A denial of service flaw was found in the way the File Information extension parsed certain Composite Document Format files. A remote attacker could use this flaw to crash a PHP application using fileinfo via a specially crafted CDF file. gd_ctx.c in the GD component in PHP 5.4.x before 5.4.32 and 5.5.x before 5.5.16 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to overwrite arbitrary files via crafted input to an application that calls the imagegd, imagegd2, imagegif, imagejpeg, imagepng, imagewbmp, or imagewebp function. The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service via a crafted color table in an XPM file. Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service via a crafted CDF file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1571 .

Platform:
Amazon Linux AMI
Product:
php55
Reference:
ALAS-2014-415
CVE-2012-1571
CVE-2014-5120
CVE-2014-2497
CVE-2014-3587
CVE    4
CVE-2012-1571
CVE-2014-5120
CVE-2014-3587
CVE-2014-2497
...
CPE    2
cpe:/o:amazon:linux
cpe:/a:php:php55

© SecPod Technologies