Description: | Summary: PHP is prone to multiple vulnerabilities.
Vulnerability Insight: The following vulnerabilities exist:
- Fixed bug #67390 (insecure temporary file use in the configure script). (CVE-2014-3981).
- Fixed bug #67498 (phpinfo() Type Confusion Information Leak Vulnerability). (CVE-2014-4721).
- Fixed bug #67326 (cdf_read_short_sector insufficient boundary check). (CVE-2014-0207).
- Fixed bug #67410 (mconvert incorrect handling of truncated pascal string size). (CVE-2014-3478).
- Fixed bug #67411 (cdf_check_stream_offset insufficient boundary check). (CVE-2014-3479).
- Fixed bug #67412 (cdf_count_chain insufficient boundary check). (CVE-2014-3480).
- Fixed bug #67413 (cdf_read_property_info insufficient boundary check). (CVE-2014-3487).
- Fixed bug #67432 (Fix potential segfault in dns_get_record()). (CVE-2014-4049).
- Fixed bug #67492 (unserialize() SPL ArrayObject / SPLObjectStorage Type Confusion). (CVE-2014-3515).
- Fixed bug #67397 (Buffer overflow in locale_get_display_name and uloc_getDisplayName (libicu 4.8.1)). (CVE-2014-9912).
Affected Software/OS: PHP versions 5.3.x before 5.3.29, 5.4.x before 5.4.30 and 5.5.x before 5.5.14.
Solution: Update to version 5.3.29, 5.4.30, 5.5.14 or later.
CVSS Score: 7.5
CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
|