CVE-2014-3480: Input Validation
The cdfcountchain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3480?
CVE-2014-3480 has a medium severity as it can lead to denial of service through application crashes.
How do I fix CVE-2014-3480?
To fix CVE-2014-3480, update your PHP version to at least 5.4.30 or 5.5.14, or upgrade to a newer version.
Which PHP versions are affected by CVE-2014-3480?
CVE-2014-3480 affects PHP versions prior to 5.4.30 and versions from 5.5.0 to 5.5.14.
What types of applications are impacted by CVE-2014-3480?
Applications using vulnerable versions of PHP for handling CDF files are impacted by CVE-2014-3480.
Is CVE-2014-3480 an exploitable vulnerability?
Yes, CVE-2014-3480 can be exploited by remote attackers to cause application crashes.