// For flags

CVE-2014-3538

file: unrestricted regular expression matching

Severity Score

6.2
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

4
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7345.

file anterior a 5.19 no restringe debidamente la cantidad de datos leídos durante una búsqueda regex, lo que permite a atacantes remotos causar una denegación de servicio (consumo de CPU) a través de un fichero manipulado que provoca un retroceso durante el procesamiento de una norma awk. NOTA: esta vulnerabilidad existe debido a una soluciona incompleta para CVE-2013-7345.

Multiple flaws were found in the File Information (fileinfo) extension regular expression rules for detecting various files. A remote attacker could use either of these flaws to cause a PHP application using fileinfo to consume an excessive amount of CPU.

Use-after-free vulnerability in ext/spl/spl_array.c in the SPL component in PHP through 5.5.14 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact via crafted ArrayIterator usage within applications in certain web-hosting environments. Use-after-free vulnerability in ext/spl/spl_dllist.c in the SPL component in PHP through 5.5.14 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact via crafted iterator usage within applications in certain web-hosting environments. file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service via a crafted file that triggers backtracking during processing of an awk rule. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7345. The updated php packages have been upgraded to the 5.5.15 version and patched to resolve these security flaws. Additionally, the jsonc extension has been upgraded to the 1.3.6 version and the PECL packages which requires so has been rebuilt for php-5.5.15.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-05-14 CVE Reserved
  • 2014-07-03 CVE Published
  • 2024-08-06 CVE Updated
  • 2024-08-06 First Exploit
  • 2025-05-15 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-399: Resource Management Errors
CAPEC
References (23)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Christos Zoulas
Search vendor "Christos Zoulas"
File
Search vendor "Christos Zoulas" for product "File"
<= 5.18
Search vendor "Christos Zoulas" for product "File" and version " <= 5.18"
-
Affected
Christos Zoulas
Search vendor "Christos Zoulas"
File
Search vendor "Christos Zoulas" for product "File"
5.00
Search vendor "Christos Zoulas" for product "File" and version "5.00"
-
Affected
Christos Zoulas
Search vendor "Christos Zoulas"
File
Search vendor "Christos Zoulas" for product "File"
5.01
Search vendor "Christos Zoulas" for product "File" and version "5.01"
-
Affected
Christos Zoulas
Search vendor "Christos Zoulas"
File
Search vendor "Christos Zoulas" for product "File"
5.02
Search vendor "Christos Zoulas" for product "File" and version "5.02"
-
Affected
Christos Zoulas
Search vendor "Christos Zoulas"
File
Search vendor "Christos Zoulas" for product "File"
5.03
Search vendor "Christos Zoulas" for product "File" and version "5.03"
-
Affected
Christos Zoulas
Search vendor "Christos Zoulas"
File
Search vendor "Christos Zoulas" for product "File"
5.04
Search vendor "Christos Zoulas" for product "File" and version "5.04"
-
Affected
Christos Zoulas
Search vendor "Christos Zoulas"
File
Search vendor "Christos Zoulas" for product "File"
5.05
Search vendor "Christos Zoulas" for product "File" and version "5.05"
-
Affected
Christos Zoulas
Search vendor "Christos Zoulas"
File
Search vendor "Christos Zoulas" for product "File"
5.06
Search vendor "Christos Zoulas" for product "File" and version "5.06"
-
Affected
Christos Zoulas
Search vendor "Christos Zoulas"
File
Search vendor "Christos Zoulas" for product "File"
5.07
Search vendor "Christos Zoulas" for product "File" and version "5.07"
-
Affected
Christos Zoulas
Search vendor "Christos Zoulas"
File
Search vendor "Christos Zoulas" for product "File"
5.08
Search vendor "Christos Zoulas" for product "File" and version "5.08"
-
Affected
Christos Zoulas
Search vendor "Christos Zoulas"
File
Search vendor "Christos Zoulas" for product "File"
5.09
Search vendor "Christos Zoulas" for product "File" and version "5.09"
-
Affected
Christos Zoulas
Search vendor "Christos Zoulas"
File
Search vendor "Christos Zoulas" for product "File"
5.10
Search vendor "Christos Zoulas" for product "File" and version "5.10"
-
Affected
Christos Zoulas
Search vendor "Christos Zoulas"
File
Search vendor "Christos Zoulas" for product "File"
5.11
Search vendor "Christos Zoulas" for product "File" and version "5.11"
-
Affected
Christos Zoulas
Search vendor "Christos Zoulas"
File
Search vendor "Christos Zoulas" for product "File"
5.12
Search vendor "Christos Zoulas" for product "File" and version "5.12"
-
Affected
Christos Zoulas
Search vendor "Christos Zoulas"
File
Search vendor "Christos Zoulas" for product "File"
5.13
Search vendor "Christos Zoulas" for product "File" and version "5.13"
-
Affected
Christos Zoulas
Search vendor "Christos Zoulas"
File
Search vendor "Christos Zoulas" for product "File"
5.14
Search vendor "Christos Zoulas" for product "File" and version "5.14"
-
Affected
Christos Zoulas
Search vendor "Christos Zoulas"
File
Search vendor "Christos Zoulas" for product "File"
5.15
Search vendor "Christos Zoulas" for product "File" and version "5.15"
-
Affected
Christos Zoulas
Search vendor "Christos Zoulas"
File
Search vendor "Christos Zoulas" for product "File"
5.16
Search vendor "Christos Zoulas" for product "File" and version "5.16"
-
Affected
Christos Zoulas
Search vendor "Christos Zoulas"
File
Search vendor "Christos Zoulas" for product "File"
5.17
Search vendor "Christos Zoulas" for product "File" and version "5.17"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
>= 5.4.0 < 5.4.32
Search vendor "Php" for product "Php" and version " >= 5.4.0 < 5.4.32"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
>= 5.5.0 < 5.5.16
Search vendor "Php" for product "Php" and version " >= 5.5.0 < 5.5.16"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
7.0
Search vendor "Debian" for product "Debian Linux" and version "7.0"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
8.0
Search vendor "Debian" for product "Debian Linux" and version "8.0"
-
Affected