PHP 'cdf_read_property_info()' Function CVE-2014-3587 Incomplete Fix Denial of Service Vulnerability
BID:69325
Info
PHP 'cdf_read_property_info()' Function CVE-2014-3587 Incomplete Fix Denial of Service Vulnerability
| Bugtraq ID: | 69325 |
| Class: | Design Error |
| CVE: |
CVE-2014-3587 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 11 2014 12:00AM |
| Updated: | Sep 21 2016 03:00PM |
| Credit: | Remi Collet |
| Vulnerable: |
Ubuntu Ubuntu Linux 14.04 LTS Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Slackware Slackware Linux 14.1 Slackware Slackware Linux 14.0 Slackware Slackware Linux 13.37 Slackware Slackware Linux 13.1 Slackware Slackware Linux 13.0 PHP PHP 5.5.12 PHP PHP 5.5.5 PHP PHP 5.5.4 PHP PHP 5.5.3 PHP PHP 5.5.1 PHP PHP 5.5 PHP PHP 5.4.26 PHP PHP 5.4.25 PHP PHP 5.4.17 PHP PHP 5.4.14 PHP PHP 5.4.2 PHP PHP 5.4.1 PHP PHP 5.5.9 PHP PHP 5.5.8 PHP PHP 5.5.2 PHP PHP 5.4.28 PHP PHP 5.4.27 PHP PHP 5.4.24 PHP PHP 5.4.23 PHP PHP 5.4.22 PHP PHP 5.4.21 PHP PHP 5.4.20 PHP PHP 5.4.19 PHP PHP 5.4.18 PHP PHP 5.4.16 PHP PHP 5.4.15 PHP PHP 5.4.13 PHP PHP 5.4.12 PHP PHP 5.4.11 PHP PHP 5.4.10 Oracle Linux 0 Oracle Enterprise Linux 7 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 IBM SmartCloud Entry 3.2 Fix Pack 18 IBM SmartCloud Entry 3.2 fix pack 14 IBM SmartCloud Entry 3.2 Fix Pack 11 IBM SmartCloud Entry 3.2 Appliance fix pack 2 IBM SmartCloud Entry 3.2 IBM SmartCloud Entry 3.1 fix pack 13 IBM SmartCloud Entry 3.1 Fix Pack 10 IBM SmartCloud Entry 3.1 IBM SmartCloud Entry 2.4 Appliance fix pack 4 IBM SmartCloud Entry 2.3 Fix Pack 1 IBM SmartCloud Entry 2.3 Appliance fix pack 6 IBM SmartCloud Entry 2.3 Appliance fix pack 4 IBM SmartCloud Entry 2.2 Fix Pack 2 IBM SmartCloud Entry 2.2 Fix Pack 1 IBM SmartCloud Entry 2.2 Appliance fix pack 6 IBM SmartCloud Entry 2.2 Appliance fix pack 4 IBM SmartCloud Entry 2.2 IBM SmartCloud Entry 3.2.0.4 IBM SmartCloud Entry 3.2.0.3 IBM SmartCloud Entry 3.2.0.2 IBM SmartCloud Entry 3.2.0.1 IBM SmartCloud Entry 3.2.0.0 IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 IBM SmartCloud Entry 3.1.0.3 IBM SmartCloud Entry 3.1.0.2 IBM SmartCloud Entry 3.1.0.1 IBM SmartCloud Entry 2.4.0.4 Appliance Fi IBM SmartCloud Entry 2.4.0.4 Appliance Fi IBM SmartCloud Entry 2.4.0.3 Appliance FP IBM SmartCloud Entry 2.4.0 fix pack 1 IBM SmartCloud Entry 2.4.0 IBM SmartCloud Entry 2.3.0.4 Appliance FP IBM SmartCloud Entry 2.3.0.4 Appliance FP IBM SmartCloud Entry 2.3.0.4 Appliance Fi IBM SmartCloud Entry 2.3.0.4 Appliance Fi IBM SmartCloud Entry 2.3.0.3 JRE Update 4 IBM SmartCloud Entry 2.3.0.3 Appliance FP IBM SmartCloud Entry 2.3.0.3 Appliance FP IBM SmartCloud Entry 2.3.0 IBM SmartCloud Entry 2.2.0.4 Appliance Fi IBM SmartCloud Entry 2.2.0.4 Appliance Fi IBM SmartCloud Entry 2.2.0.3 Appliance FP IBM Security Network Protection 5.3.2 IBM Security Network Protection 5.3.1 IBM PowerKVM 3.1 IBM PowerKVM 2.1 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 6 Avaya IP Office Server Edition 9.0 Avaya IP Office Server Edition 8.1 Avaya IP Office Application Server 9.0 Avaya Aura Session Manager 5.2.4 Avaya Aura Session Manager 5.2.1 Avaya Aura Session Manager 5.2 SP2 Avaya Aura Session Manager 5.2 SP1 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 5.0 Avaya Aura Experience Portal 6.0.2 Avaya Aura Experience Portal 6.0.1 Avaya Aura Experience Portal 7.0 Avaya Aura Experience Portal 6.0 Avaya Aura Conferencing 8.0 Avaya Aura Communication Manager Utility Services 6.3 Avaya Aura Communication Manager Utility Services 6.2.5.0.15 Avaya Aura Communication Manager Utility Services 6.2.4.0.15 Avaya Aura Communication Manager Utility Services 6.2 Avaya Aura Communication Manager Utility Services 6.1.0.9.8 Avaya Aura Communication Manager Utility Services 6.1 SP 6.1.0.9.8 Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Apple Mac OS X 10.9.5 Apple Mac OS X 10.8.5 Apple Mac OS X 10.10.2 Apple Mac OS X 10.10.1 Apple Mac OS X 10.10 AlienVault AlienVault 4.12 |
| Not Vulnerable: |
IBM PowerKVM 2.1.1 SP3 IBM PowerKVM 2.1.1 Build 65.6 IBM PowerKVM 3.1 Build 3 Apple Mac Os X 10.10.3 AlienVault AlienVault 4.13 |
Discussion
PHP 'cdf_read_property_info()' Function CVE-2014-3587 Incomplete Fix Denial of Service Vulnerability
PHP is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to cause the affected application to crash, denying service to legitimate users.
Note: This issue is the result of an incomplete fix for the issue described in 66406 (PHP Fileinfo Component Remote Denial of Service Vulnerability).
PHP is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to cause the affected application to crash, denying service to legitimate users.
Note: This issue is the result of an incomplete fix for the issue described in 66406 (PHP Fileinfo Component Remote Denial of Service Vulnerability).
Exploit / POC
PHP 'cdf_read_property_info()' Function CVE-2014-3587 Incomplete Fix Denial of Service Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
PHP 'cdf_read_property_info()' Function CVE-2014-3587 Incomplete Fix Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
PHP 'cdf_read_property_info()' Function CVE-2014-3587 Incomplete Fix Denial of Service Vulnerability
References:
References:
- [PHP] #67716 Segfault in cdf.c (PHP)
- PHP Homepage (PHP)
- Security Advisory, AlienVault v4.13 addresses (14) vulnerabilities (AlienVault)
- isg3T1023349 Multiple vulnerabilities in file affect PowerKVM (IBM)
- isg3T1024195:File vulnerabilities affect IBM SmartClound Entry (IBM)
- php53 and php security update (RHSA-2014-1326) (Avaya)
- Ref: linuxbulletinoct2015-2719645 Oracle Linux Bulletin - October 2015 Revision (Oracle)
- swg21985753:Multiple vulnerabilities in file affect IBM Security Network Protect (IBM)