CVE-2014-9912: Buffer Overflow
The geticudispvaluesrcphp function in ext/intl/locale/localemethods.c in PHP before 5.3.29, 5.4.x before 5.4.30, and 5.5.x before 5.5.14 does not properly restrict calls to the ICU uresbund.cpp component, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a localegetdisplayname call with a long first argument.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9912?
CVE-2014-9912 has a severity rating of medium due to its potential to cause denial of service or a buffer overflow.
How do I fix CVE-2014-9912?
To fix CVE-2014-9912, update PHP to version 5.3.29, 5.4.30, or 5.5.14 or later.
Which versions of PHP are affected by CVE-2014-9912?
CVE-2014-9912 affects PHP versions before 5.3.29, all 5.4.x versions before 5.4.30, and all 5.5.x versions before 5.5.14.
What types of attacks can exploit CVE-2014-9912?
CVE-2014-9912 can be exploited to perform denial of service attacks, potentially leading to application crashes.
Is there a workaround for CVE-2014-9912?
The best approach for CVE-2014-9912 is upgrading to the fixed versions, as no effective workaround is provided.