PHP 'cdf_unpack_summary_info()' Function Denial of Service Vulnerability
BID:67759
Info
PHP 'cdf_unpack_summary_info()' Function Denial of Service Vulnerability
| Bugtraq ID: | 67759 |
| Class: | Design Error |
| CVE: |
CVE-2014-0237 |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2014 12:00AM |
| Updated: | Jul 05 2016 09:41PM |
| Credit: | Remi Collet |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE openSUSE 11.4 Slackware Slackware Linux 13.37 Slackware Slackware Linux 13.1 Slackware Slackware Linux 13.0 RedHat Enterprise Linux Desktop Workstation 5 client Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux 5 Server PHP PHP 5.4.2 PHP PHP 5.4.1 PHP PHP 5.3.13 PHP PHP 5.3.12 PHP PHP 5.3.9 PHP PHP 5.3.8 PHP PHP 5.3.7 PHP PHP 5.3.6 PHP PHP 5.3.5 PHP PHP 5.3.2 PHP PHP 5.3.1 PHP PHP 5.3 PHP PHP 5.2.17 PHP PHP 5.2.15 PHP PHP 5.2.13 PHP PHP 5.2.12 PHP PHP 5.2.11 PHP PHP 5.2.10 PHP PHP 5.2.9 PHP PHP 5.2.8 PHP PHP 5.2.7 PHP PHP 5.2.6 PHP PHP 5.2.5 PHP PHP 5.2.4 PHP PHP 5.2.3 PHP PHP 5.2.2 PHP PHP 5.2.1 PHP PHP 5.1.6 PHP PHP 5.1.5 PHP PHP 5.1.4 PHP PHP 5.1.3 PHP PHP 5.1.2 PHP PHP 5.1.1 PHP PHP 5.1 PHP PHP 5.0.5 PHP PHP 5.0.4 PHP PHP 5.0.3 PHP PHP 5.0.2 PHP PHP 5.0.1 PHP PHP 5.3.4 PHP PHP 5.3.3 PHP PHP 5.3.11 PHP PHP 5.3.10 PHP PHP 5.2.14 PHP PHP 5.2 Oracle Linux 0 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 6 |
| Not Vulnerable: | |
Discussion
PHP 'cdf_unpack_summary_info()' Function Denial of Service Vulnerability
PHP is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to cause the affected application to hang, denying service to legitimate users.
PHP versions prior to 5.4.29 and 5.5.0 through 5.5.13 are vulnerable.
PHP is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to cause the affected application to hang, denying service to legitimate users.
PHP versions prior to 5.4.29 and 5.5.0 through 5.5.13 are vulnerable.
Exploit / POC
PHP 'cdf_unpack_summary_info()' Function Denial of Service Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
PHP 'cdf_unpack_summary_info()' Function Denial of Service Vulnerability
References:
References:
- Sec Bug #67328 fileinfo: numerous file_printf calls resulting in performance de (PHP)
- PHP Homepage (PHP)
- Security Advisory, AlienVault v4.13 addresses (14) vulnerabilities (AlienVault)
- isg3T1023349 Multiple vulnerabilities in file affect PowerKVM (IBM)
- Ref: linuxbulletinoct2015-2719645 Oracle Linux Bulletin - October 2015 Revision (Oracle)
- RHSA-2014:1012-1 Moderate: php53 and php security update (Red Hat)
- Security Bulletin: Multiple vulnerabilities in PHP 5.2 open source component for (IBM)
- Security Bulletin: Multiple vulnerabilities in PHP as used by IBM QRadar Inciden (IBM)