PHP 'donote()' Function Out-of-Bounds Read Vulnerability
BID:70807
Info
PHP 'donote()' Function Out-of-Bounds Read Vulnerability
| Bugtraq ID: | 70807 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2014-3710 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 22 2014 12:00AM |
| Updated: | Jan 23 2017 09:11AM |
| Credit: | Francisco Alonso |
| Vulnerable: |
Ubuntu Ubuntu Linux 14.10 Ubuntu Ubuntu Linux 14.04 LTS Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Slackware Slackware Linux 14.1 Slackware Slackware Linux 14.0 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux 5 Server PHP PHP 5.4.34 Pexip Pexip Infinity 8.0 Pexip Pexip Infinity 7.0 Pexip Pexip Infinity 6.0 Pexip Pexip Infinity 5.0 Pexip Pexip Infinity 4.0 Pexip Pexip Infinity 3.0 Pexip Pexip Infinity 2.0 Pexip Pexip Infinity 1.0 Oracle Linux 0 Oracle Enterprise Linux 7 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 IBM SmartCloud Entry 3.2 Fix Pack 18 IBM SmartCloud Entry 3.2 fix pack 14 IBM SmartCloud Entry 3.2 Fix Pack 11 IBM SmartCloud Entry 3.2 Appliance fix pack 2 IBM SmartCloud Entry 3.2 IBM SmartCloud Entry 3.1 fix pack 13 IBM SmartCloud Entry 3.1 Fix Pack 10 IBM SmartCloud Entry 3.1 IBM SmartCloud Entry 2.4 Appliance fix pack 4 IBM SmartCloud Entry 2.3 Fix Pack 1 IBM SmartCloud Entry 2.3 Appliance fix pack 6 IBM SmartCloud Entry 2.3 Appliance fix pack 4 IBM SmartCloud Entry 2.2 Fix Pack 2 IBM SmartCloud Entry 2.2 Fix Pack 1 IBM SmartCloud Entry 2.2 Appliance fix pack 6 IBM SmartCloud Entry 2.2 Appliance fix pack 4 IBM SmartCloud Entry 2.2 IBM SmartCloud Entry 3.2.0.4 IBM SmartCloud Entry 3.2.0.3 IBM SmartCloud Entry 3.2.0.2 IBM SmartCloud Entry 3.2.0.1 IBM SmartCloud Entry 3.2.0.0 IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 IBM SmartCloud Entry 3.1.0.3 IBM SmartCloud Entry 3.1.0.2 IBM SmartCloud Entry 3.1.0.1 IBM SmartCloud Entry 2.4.0.4 Appliance Fi IBM SmartCloud Entry 2.4.0.4 Appliance Fi IBM SmartCloud Entry 2.4.0.3 Appliance FP IBM SmartCloud Entry 2.4.0 fix pack 1 IBM SmartCloud Entry 2.4.0 IBM SmartCloud Entry 2.3.0.4 Appliance FP IBM SmartCloud Entry 2.3.0.4 Appliance FP IBM SmartCloud Entry 2.3.0.4 Appliance Fi IBM SmartCloud Entry 2.3.0.4 Appliance Fi IBM SmartCloud Entry 2.3.0.3 JRE Update 4 IBM SmartCloud Entry 2.3.0.3 Appliance FP IBM SmartCloud Entry 2.3.0.3 Appliance FP IBM SmartCloud Entry 2.3.0 IBM SmartCloud Entry 2.2.0.4 Appliance Fi IBM SmartCloud Entry 2.2.0.4 Appliance Fi IBM SmartCloud Entry 2.2.0.3 Appliance FP IBM Security Network Protection 5.3.2 IBM Security Network Protection 5.3.1 IBM PowerKVM 3.1 IBM PowerKVM 2.1 Gentoo Linux FreeBSD FreeBSD 0 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 6 CentOS CentOS 5 Apple Mac OS X 10.9.5 Apple Mac OS X 10.8.5 Apple Mac OS X 10.10.2 Apple Mac OS X 10.10.1 Apple Mac OS X 10.10 |
| Not Vulnerable: |
Pexip Pexip Infinity 9.0 IBM PowerKVM 2.1.1 SP3 IBM PowerKVM 2.1.1 Build 65.6 IBM PowerKVM 3.1 Build 3 FreeBSD FreeBSD 9.3-STABLE FreeBSD FreeBSD 9.3-RELEASE-p6 FreeBSD FreeBSD 9.2-RELEASE-p16 FreeBSD FreeBSD 9.1-RELEASE-p23 FreeBSD FreeBSD 8.4-STABLE FreeBSD FreeBSD 8.4-RELEASE-p20 FreeBSD FreeBSD 10.1-STABLE FreeBSD FreeBSD 10.1-RELEASE-p1 FreeBSD FreeBSD 10.0-RELEASE-p13 Apple Mac Os X 10.10.3 |
Discussion
PHP 'donote()' Function Out-of-Bounds Read Vulnerability
PHP is prone to an out-of-bounds read vulnerability.
Attackers can exploit this issue to crash the application denying service to legitimate users or disclose sensitive information that may aid in further attacks.
PHP version 5.4.34 is vulnerable; other versions may also be affected.
PHP is prone to an out-of-bounds read vulnerability.
Attackers can exploit this issue to crash the application denying service to legitimate users or disclose sensitive information that may aid in further attacks.
PHP version 5.4.34 is vulnerable; other versions may also be affected.
Exploit / POC
PHP 'donote()' Function Out-of-Bounds Read Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
PHP 'donote()' Function Out-of-Bounds Read Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
PHP 'donote()' Function Out-of-Bounds Read Vulnerability
References:
References:
- Fix note bounds reading, Francisco Alonso / Red Hat (github)
- Sec Bug #68283 fileinfo: out-of-bounds read in elf note headers (PHP)
- FreeBSD-SA-14:28.file - Multiple vulnerabilities in file(1) and libmagic(3) (FreeBSD)
- isg3T1023349 Multiple vulnerabilities in file affect PowerKVM (IBM)
- isg3T1024195:File vulnerabilities affect IBM SmartClound Entry (IBM)
- pexip Security Bulletin: Multiple vulnerabilities (Pexip)
- Ref: linuxbulletinoct2015-2719645 Oracle Linux Bulletin - October 2015 Revision (Oracle)
- swg21985753:Multiple vulnerabilities in file affect IBM Security Network Protect (IBM)