CVE-2014-3478: Buffer Overflow
Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (application crash) via a crafted Pascal string in a FILEPSTRING conversion.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3478?
CVE-2014-3478 has a severity level that can lead to denial of service due to a buffer overflow issue.
How do I fix CVE-2014-3478?
To fix CVE-2014-3478, upgrade to Software version 5.19 or higher for the affected 'file' component.
What software is affected by CVE-2014-3478?
CVE-2014-3478 affects versions of PHP before 5.4.30 and 5.5.x before 5.5.14, as well as 'file' versions before 5.19.
What type of attack does CVE-2014-3478 enable?
CVE-2014-3478 enables remote attackers to cause an application crash through crafted Pascal strings.
Can CVE-2014-3478 be exploited remotely?
Yes, CVE-2014-3478 can be exploited remotely via specially crafted inputs to the vulnerable functions.