Back

HIGH

php: denial of service in libmagic/apprentice.c

Published Dec 31, 2014

Description

The apprentice_load function in libmagic/apprentice.c in the Fileinfo component in PHP through 5.6.4 attempts to perform a free operation on a stack-based character array, which allows remote attackers to cause a denial of service (memory corruption or application crash) or possibly have unspecified other impact via unknown vectors. NOTE: this is disputed by the vendor because the standard erealloc behavior makes the free operation unreachable

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Dec 31, 2014
Updated Oct 29, 2024
Reserved Dec 29, 2014

CISA Vulnrichment

Updated Jun 18, 2024

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Public date Dec 28, 2014
Bugzilla 1178715

ENISA EUVD

Assigner mitre
Published Dec 31, 2014
Updated Oct 29, 2024

GitHub

No data