CVE-2014-3587: Integer Overflow
Integer overflow in the cdfreadpropertyinfo function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1571.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3587?
CVE-2014-3587 has a high severity due to the potential for denial of service attacks resulting in application crashes.
How do I fix CVE-2014-3587?
To fix CVE-2014-3587, upgrade to a version of the 'file' package that is 5.39 or higher.
What software is affected by CVE-2014-3587?
CVE-2014-3587 affects the 'file' package versions up to and including 5.19 and PHP versions before 5.4.32 and 5.5.x before 5.5.16.
Can attacking with a crafted CDF file exploit CVE-2014-3587?
Yes, attackers can exploit CVE-2014-3587 by sending crafted CDF files that can cause application crashes.
Is there a patch available for CVE-2014-3587?
Yes, patches are available in the newer versions of the 'file' package and PHP versions that address CVE-2014-3587.