CVE-2014-0237
file: cdf_unpack_summary_info() excessive looping DoS
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The cdf_unpack_summary_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (performance degradation) by triggering many file_printf calls.
La función cdf_unpack_summary_info en cdf.c en el componente Fileinfo en PHP anterior a 5.4.29 y 5.5.x anterior a 5.5.13 permite a atacantes remotos causar una denegación de servicio (degradación de rendimiento) mediante la provocación de muchas llamadas file_printf.
A denial of service flaw was found in the way the File Information (fileinfo) extension parsed certain Composite Document Format (CDF) files. A remote attacker could use this flaw to crash a PHP application using fileinfo via a specially crafted CDF file.
A flaw was found in the way file's Composite Document Files format parser handle CDF files with many summary info entries. The cdf_unpack_summary_info() function unnecessarily repeatedly read the info from the same offset. This led to many file_printf() calls in cdf_file_property_info(), which caused file to use an excessive amount of CPU time when parsing a specially-crafted CDF file. A flaw was found in the way file parsed property information from Composite Document Files files. A property entry with 0 elements triggers an infinite loop. PHP contains a bundled copy of the file utility's libmagic library, so it was vulnerable to this issue. It has been updated to the 5.5.13 version, which fixes this issue and several other bugs. Additionally, php-apc has been rebuilt against the updated php packages.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-12-03 CVE Reserved
- 2014-06-01 CVE Published
- 2024-08-06 CVE Updated
- 2025-04-14 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-399: Resource Management Errors
- CWE-407: Inefficient Algorithmic Complexity
CAPEC
References (20)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/59061 | Third Party Advisory | |
http://secunia.com/advisories/59329 | Third Party Advisory | |
http://secunia.com/advisories/59418 | Third Party Advisory | |
http://secunia.com/advisories/60998 | Third Party Advisory | |
http://support.apple.com/kb/HT6443 | Third Party Advisory |
|
http://www-01.ibm.com/support/docview.wss?uid=swg21683486 | Third Party Advisory | |
http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html | Third Party Advisory |
|
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html | Third Party Advisory |
|
http://www.securityfocus.com/bid/67759 | Third Party Advisory | |
https://support.apple.com/HT204659 | Third Party Advisory |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://bugs.php.net/bug.php?id=67328 | 2023-01-19 | |
https://github.com/file/file/commit/b8acc83781d5a24cc5101e525d15efe0482c280d | 2023-01-19 |
URL | Date | SRC |
---|---|---|
http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html | 2023-01-19 | |
http://lists.opensuse.org/opensuse-security-announce/2014-07/msg00002.html | 2023-01-19 | |
http://rhn.redhat.com/errata/RHSA-2014-1765.html | 2023-01-19 | |
http://rhn.redhat.com/errata/RHSA-2014-1766.html | 2023-01-19 | |
http://www.debian.org/security/2014/dsa-3021 | 2023-01-19 | |
http://www.php.net/ChangeLog-5.php | 2023-01-19 | |
https://access.redhat.com/security/cve/CVE-2014-0237 | 2015-11-19 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1098193 | 2015-11-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Php Search vendor "Php" | Php Search vendor "Php" for product "Php" | < 5.3.29 Search vendor "Php" for product "Php" and version " < 5.3.29" | - |
Affected
| ||||||
Php Search vendor "Php" | Php Search vendor "Php" for product "Php" | >= 5.4.0 < 5.4.29 Search vendor "Php" for product "Php" and version " >= 5.4.0 < 5.4.29" | - |
Affected
| ||||||
Php Search vendor "Php" | Php Search vendor "Php" for product "Php" | >= 5.5.0 < 5.5.13 Search vendor "Php" for product "Php" and version " >= 5.5.0 < 5.5.13" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 7.0 Search vendor "Debian" for product "Debian Linux" and version "7.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
|