CVE-2014-8684
Summary
| CVE | CVE-2014-8684 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-19 19:29:00 UTC |
| Updated | 2017-09-28 18:47:00 UTC |
| Description | CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by leveraging use of standard string comparison operators to compare cryptographic hashes. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 3.3/develop by sarciszewski · Pull Request #492 · kohana/core · GitHub |
CONFIRM |
github.com |
Third Party Advisory |
| Full Disclosure: CodeIgniter <= 2.1.4 and Kohana <= 3.2.3, 3.3.2 - Timing Attacks and Object Injection |
FULLDISC |
seclists.org |
Mailing List, Third Party Advisory |
| Seagate Business NAS Unauthenticated Remote Command Execution ≈ Packet Storm |
MISC |
packetstormsecurity.com |
Third Party Advisory, VDB Entry |
| scott.arciszewski.me/research/full/php-framework-timing-attacks-object-injection |
MISC |
scott.arciszewski.me |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 994890 PHP (Composer) Security Update for codeigniter/framework (GHSA-w9ph-q4h9-rwq6)