CVE-2014-3587 : Detail

CVE-2014-3587

6%V3
Network
2014-08-22
23h00 +00:00
2018-01-04
18h57 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1571.

CVE Informations

Related Weaknesses

CWE-ID Weakness Name Source
CWE-189 Category : Numeric Errors
Weaknesses in this category are related to improper calculation or conversion of numbers.

Metrics

Metrics Score Severity CVSS Vector Source
V2 4.3 AV:N/AC:M/Au:N/C:N/I:N/A:P [email protected]

EPSS

EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.

EPSS Score

The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.

EPSS Percentile

The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.

Products Mentioned

Configuraton 0

Christos_zoulas>>File >> Version To (including) 5.19

Christos_zoulas>>File >> Version 5.00

Christos_zoulas>>File >> Version 5.01

Christos_zoulas>>File >> Version 5.02

Christos_zoulas>>File >> Version 5.03

Christos_zoulas>>File >> Version 5.04

Christos_zoulas>>File >> Version 5.05

Christos_zoulas>>File >> Version 5.06

Christos_zoulas>>File >> Version 5.07

Christos_zoulas>>File >> Version 5.08

Christos_zoulas>>File >> Version 5.09

Christos_zoulas>>File >> Version 5.10

Christos_zoulas>>File >> Version 5.11

Christos_zoulas>>File >> Version 5.12

Christos_zoulas>>File >> Version 5.13

Christos_zoulas>>File >> Version 5.14

Christos_zoulas>>File >> Version 5.15

Christos_zoulas>>File >> Version 5.16

Christos_zoulas>>File >> Version 5.17

Christos_zoulas>>File >> Version 5.18

Php>>Php >> Version To (including) 5.4.31

Php>>Php >> Version 5.4.0

Php>>Php >> Version 5.4.0

Php>>Php >> Version 5.4.0

    Php>>Php >> Version 5.4.0

    Php>>Php >> Version 5.4.1

    Php>>Php >> Version 5.4.2

    Php>>Php >> Version 5.4.3

    Php>>Php >> Version 5.4.4

    Php>>Php >> Version 5.4.5

    Php>>Php >> Version 5.4.6

    Php>>Php >> Version 5.4.7

    Php>>Php >> Version 5.4.8

    Php>>Php >> Version 5.4.9

    Php>>Php >> Version 5.4.10

    Php>>Php >> Version 5.4.11

    Php>>Php >> Version 5.4.12

    Php>>Php >> Version 5.4.12

    Php>>Php >> Version 5.4.12

    Php>>Php >> Version 5.4.13

    Php>>Php >> Version 5.4.13

    Php>>Php >> Version 5.4.14

    Php>>Php >> Version 5.4.14

    Php>>Php >> Version 5.4.15

    Php>>Php >> Version 5.4.15

    Php>>Php >> Version 5.4.16

    Php>>Php >> Version 5.4.17

    Php>>Php >> Version 5.4.18

    Php>>Php >> Version 5.4.19

    Php>>Php >> Version 5.4.20

    Php>>Php >> Version 5.4.21

    Php>>Php >> Version 5.4.22

    Php>>Php >> Version 5.4.23

    Php>>Php >> Version 5.4.24

    Php>>Php >> Version 5.4.25

    Php>>Php >> Version 5.4.26

    Php>>Php >> Version 5.4.27

    Php>>Php >> Version 5.4.28

    Php>>Php >> Version 5.4.29

    Php>>Php >> Version 5.4.30

    Php>>Php >> Version 5.5.0

    Php>>Php >> Version 5.5.0

    Php>>Php >> Version 5.5.0

    Php>>Php >> Version 5.5.0

    Php>>Php >> Version 5.5.0

    Php>>Php >> Version 5.5.0

    Php>>Php >> Version 5.5.0

    Php>>Php >> Version 5.5.0

    Php>>Php >> Version 5.5.0

    Php>>Php >> Version 5.5.0

    Php>>Php >> Version 5.5.0

    Php>>Php >> Version 5.5.0

    Php>>Php >> Version 5.5.0

    Php>>Php >> Version 5.5.1

    Php>>Php >> Version 5.5.2

    Php>>Php >> Version 5.5.3

    Php>>Php >> Version 5.5.4

    Php>>Php >> Version 5.5.5

    Php>>Php >> Version 5.5.6

    Php>>Php >> Version 5.5.7

    Php>>Php >> Version 5.5.8

    Php>>Php >> Version 5.5.9

    Php>>Php >> Version 5.5.10

    Php>>Php >> Version 5.5.11

    Php>>Php >> Version 5.5.12

    Php>>Php >> Version 5.5.13

    Php>>Php >> Version 5.5.14

    Php>>Php >> Version 5.5.15

    References

    https://support.apple.com/HT204659
    Tags : x_refsource_CONFIRM
    http://www.ubuntu.com/usn/USN-2369-1
    Tags : vendor-advisory, x_refsource_UBUNTU
    http://rhn.redhat.com/errata/RHSA-2014-1766.html
    Tags : vendor-advisory, x_refsource_REDHAT
    http://www.debian.org/security/2014/dsa-3021
    Tags : vendor-advisory, x_refsource_DEBIAN
    http://secunia.com/advisories/60609
    Tags : third-party-advisory, x_refsource_SECUNIA
    http://www.ubuntu.com/usn/USN-2344-1
    Tags : vendor-advisory, x_refsource_UBUNTU
    http://rhn.redhat.com/errata/RHSA-2016-0760.html
    Tags : vendor-advisory, x_refsource_REDHAT
    http://php.net/ChangeLog-5.php
    Tags : x_refsource_CONFIRM
    http://rhn.redhat.com/errata/RHSA-2014-1326.html
    Tags : vendor-advisory, x_refsource_REDHAT
    http://www.debian.org/security/2014/dsa-3008
    Tags : vendor-advisory, x_refsource_DEBIAN
    http://rhn.redhat.com/errata/RHSA-2014-1327.html
    Tags : vendor-advisory, x_refsource_REDHAT
    http://www.securityfocus.com/bid/69325
    Tags : vdb-entry, x_refsource_BID
    http://rhn.redhat.com/errata/RHSA-2014-1765.html
    Tags : vendor-advisory, x_refsource_REDHAT
    https://bugs.php.net/bug.php?id=67716
    Tags : x_refsource_CONFIRM
    http://secunia.com/advisories/60696
    Tags : third-party-advisory, x_refsource_SECUNIA