Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.809736
Category:Web application abuses
Title:PHP Multiple Vulnerabilities (Jun/Aug 2014) - Linux
Summary:PHP is prone to multiple vulnerabilities.
Description:Summary:
PHP is prone to multiple vulnerabilities.

Vulnerability Insight:
The following vulnerabilities exist:

- Fixed bug #67390 (insecure temporary file use in the configure script). (CVE-2014-3981).

- Fixed bug #67498 (phpinfo() Type Confusion Information Leak Vulnerability). (CVE-2014-4721).

- Fixed bug #67326 (cdf_read_short_sector insufficient boundary check). (CVE-2014-0207).

- Fixed bug #67410 (mconvert incorrect handling of truncated pascal string size). (CVE-2014-3478).

- Fixed bug #67411 (cdf_check_stream_offset insufficient boundary check). (CVE-2014-3479).

- Fixed bug #67412 (cdf_count_chain insufficient boundary check). (CVE-2014-3480).

- Fixed bug #67413 (cdf_read_property_info insufficient boundary check). (CVE-2014-3487).

- Fixed bug #67432 (Fix potential segfault in dns_get_record()). (CVE-2014-4049).

- Fixed bug #67492 (unserialize() SPL ArrayObject / SPLObjectStorage Type Confusion).
(CVE-2014-3515).

- Fixed bug #67397 (Buffer overflow in locale_get_display_name and uloc_getDisplayName (libicu
4.8.1)). (CVE-2014-9912).

Affected Software/OS:
PHP versions 5.3.x before 5.3.29, 5.4.x before 5.4.30 and 5.5.x
before 5.5.14.

Solution:
Update to version 5.3.29, 5.4.30, 5.5.14 or later.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2014-3981
http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html
http://seclists.org/fulldisclosure/2014/Jun/21
HPdes Security Advisory: HPSBUX03102
http://marc.info/?l=bugtraq&m=141017844705317&w=2
HPdes Security Advisory: HPSBUX03150
http://marc.info/?l=bugtraq&m=141390017113542&w=2
HPdes Security Advisory: SSRT101681
http://openwall.com/lists/oss-security/2014/06/06/12
Common Vulnerability Exposure (CVE) ID: CVE-2014-4721
Debian Security Information: DSA-2974 (Google Search)
http://www.debian.org/security/2014/dsa-2974
http://twitter.com/mikispag/statuses/485713462258302976
https://www.sektioneins.de/en/blog/14-07-04-phpinfo-infoleak.html
RedHat Security Advisories: RHSA-2014:1765
http://rhn.redhat.com/errata/RHSA-2014-1765.html
RedHat Security Advisories: RHSA-2014:1766
http://rhn.redhat.com/errata/RHSA-2014-1766.html
http://secunia.com/advisories/54553
http://secunia.com/advisories/59794
http://secunia.com/advisories/59831
SuSE Security Announcement: openSUSE-SU-2014:0945 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-07/msg00035.html
SuSE Security Announcement: openSUSE-SU-2014:1236 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-09/msg00046.html
Common Vulnerability Exposure (CVE) ID: CVE-2014-0207
59794
59831
68243
http://www.securityfocus.com/bid/68243
APPLE-SA-2015-04-08-2
DSA-2974
DSA-3021
http://www.debian.org/security/2014/dsa-3021
HPSBUX03102
RHSA-2014:1765
RHSA-2014:1766
SSRT101681
[file] 20140612 file-5.19 is now available
http://mx.gw.com/pipermail/file/2014/001553.html
http://support.apple.com/kb/HT6443
http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
http://www.php.net/ChangeLog-5.php
https://bugs.php.net/bug.php?id=67326
https://bugzilla.redhat.com/show_bug.cgi?id=1091842
https://github.com/file/file/commit/6d209c1c489457397a5763bca4b28e43aac90391
https://support.apple.com/HT204659
openSUSE-SU-2014:1236
Common Vulnerability Exposure (CVE) ID: CVE-2014-3478
68239
http://www.securityfocus.com/bid/68239
RHSA-2014:1327
http://rhn.redhat.com/errata/RHSA-2014-1327.html
https://bugs.php.net/bug.php?id=67410
https://github.com/file/file/commit/27a14bc7ba285a0a5ebfdb55e54001aa11932b08
Common Vulnerability Exposure (CVE) ID: CVE-2014-3479
68241
http://www.securityfocus.com/bid/68241
https://bugs.php.net/bug.php?id=67411
https://github.com/file/file/commit/36fadd29849b8087af9f4586f89dbf74ea45be67
Common Vulnerability Exposure (CVE) ID: CVE-2014-3480
68238
http://www.securityfocus.com/bid/68238
https://bugs.php.net/bug.php?id=67412
https://github.com/file/file/commit/40bade80cbe2af1d0b2cd0420cebd5d5905a2382
Common Vulnerability Exposure (CVE) ID: CVE-2014-3487
68120
http://www.securityfocus.com/bid/68120
https://bugs.php.net/bug.php?id=67413
https://github.com/file/file/commit/93e063ee374b6a75729df9e7201fb511e47e259d
Common Vulnerability Exposure (CVE) ID: CVE-2014-4049
BugTraq ID: 68007
http://www.securityfocus.com/bid/68007
Debian Security Information: DSA-2961 (Google Search)
http://www.debian.org/security/2014/dsa-2961
http://www.openwall.com/lists/oss-security/2014/06/13/4
http://www.securitytracker.com/id/1030435
http://secunia.com/advisories/59270
http://secunia.com/advisories/59329
http://secunia.com/advisories/59418
http://secunia.com/advisories/59496
http://secunia.com/advisories/59513
http://secunia.com/advisories/59652
http://secunia.com/advisories/60998
SuSE Security Announcement: SUSE-SU-2014:0868 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2014-07/msg00001.html
SuSE Security Announcement: SUSE-SU-2014:0869 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2014-07/msg00002.html
SuSE Security Announcement: openSUSE-SU-2014:0841 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-06/msg00051.html
SuSE Security Announcement: openSUSE-SU-2014:0942 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-07/msg00032.html
Common Vulnerability Exposure (CVE) ID: CVE-2014-3515
BugTraq ID: 68237
http://www.securityfocus.com/bid/68237
Common Vulnerability Exposure (CVE) ID: CVE-2014-9912
BugTraq ID: 68549
http://www.securityfocus.com/bid/68549
http://www.openwall.com/lists/oss-security/2016/11/25/1
CopyrightCopyright (C) 2016 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.