php5: CVE-2014-2270: out-of-bounds memory access in fileinfo

Related Vulnerabilities: CVE-2014-2270  

Debian Bug report logs - #740960
php5: CVE-2014-2270: out-of-bounds memory access in fileinfo

version graph

Reported by: Salvatore Bonaccorso <carnil@debian.org>

Date: Thu, 6 Mar 2014 17:57:02 UTC

Severity: important

Tags: fixed-upstream, security, upstream

Found in version php5/5.4.4-14+deb7u9

Fixed in versions php5/5.5.10+dfsg-1, php5/5.4.4-14+deb7u10

Done: Ondřej Surý <ondrej@sury.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, carnil@debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>:
Bug#740960; Package src:php5. (Thu, 06 Mar 2014 17:57:06 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
New Bug report received and forwarded. Copy sent to carnil@debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>. (Thu, 06 Mar 2014 17:57:06 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: php5: CVE-2014-2270: out-of-bounds memory access in fileinfo
Date: Thu, 06 Mar 2014 18:55:10 +0100
Source: php5
Severity: important
Tags: security upstream fixed-upstream

Hi

Another CVE was assigned for a issue in file/libmagic also affecting
the embedded copy in php5. It has assigned CVE-2014-2270[1]. php5
bugreport is at [2] and a fix already commited [3].

 [1] https://security-tracker.debian.org/tracker/CVE-2014-2270
 [2] https://bugs.php.net/bug.php?id=66820
 [3] http://git.php.net/?p=php-src.git;a=commitdiff;h=a33759fd275b32ed0bbe89796fe2953b3cb0b41f

Regards,
Salvatore



Marked as fixed in versions php5/5.5.10+dfsg-1. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Thu, 27 Mar 2014 19:45:04 GMT) (full text, mbox, link).


Reply sent to Ondřej Surý <ondrej@sury.org>:
You have taken responsibility. (Wed, 02 Jul 2014 12:21:23 GMT) (full text, mbox, link).


Notification sent to Salvatore Bonaccorso <carnil@debian.org>:
Bug acknowledged by developer. (Wed, 02 Jul 2014 12:21:23 GMT) (full text, mbox, link).


Message #12 received at 740960-done@bugs.debian.org (full text, mbox, reply):

From: Ondřej Surý <ondrej@sury.org>
To: 740960-done@bugs.debian.org
Subject: Re: Bug#740960: php5: CVE-2014-2270: out-of-bounds memory access in fileinfo
Date: Wed, 02 Jul 2014 14:17:27 +0200
Control: found -1 php5/5.4.4-14+deb7u9
Version: php5/5.4.4-14+deb7u10

And I believe we have fixed rest of the fileinfo bugs in
5.4.4-14+deb7u12

Cheers,
-- 
Ondřej Surý <ondrej@sury.org>
Knot DNS (https://www.knot-dns.cz/) – a high-performance DNS server



Marked as found in versions php5/5.4.4-14+deb7u9. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Wed, 02 Jul 2014 18:51:08 GMT) (full text, mbox, link).


Marked as fixed in versions php5/5.4.4-14+deb7u10. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Wed, 02 Jul 2014 19:03:10 GMT) (full text, mbox, link).


Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sat, 04 Oct 2014 07:35:02 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 14:57:54 2019; Machine Name: beach

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.