A denial of service flaw was found in the way the File Information (fileinfo) extension parsed certain Composite Document Format (CDF) files. A remote attacker could use this flaw to crash a PHP application using fileinfo via a specially crafted CDF file.
Find out more about CVE-2014-0237 from the MITRE CVE dictionary dictionary and NIST NVD.
This issue did not affect the php and the file packages as shipped with Red Hat Enterprise Linux 5.
This issue affects the versions of file as shipped with Red Hat Enterprise Linux 7. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Base Score | 4.3 |
---|---|
Base Metrics | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Access Vector | Network |
Access Complexity | Medium |
Authentication | None |
Confidentiality Impact | None |
Integrity Impact | None |
Availability Impact | Partial |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).
Platform | Errata | Release Date |
---|---|---|
Red Hat Enterprise Linux 5 (php53) | RHSA-2014:1012 | 2014-08-06 |
Red Hat Enterprise Linux 6 (php) | RHSA-2014:1012 | 2014-08-06 |
Red Hat Enterprise Linux 7 (file) | RHSA-2015:2155 | 2015-11-19 |
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 (php54-php) | RHSA-2014:1765 | 2014-10-30 |
Red Hat Software Collections 1 for Red Hat Enterprise Linux 7 (php54-php) | RHSA-2014:1765 | 2014-10-30 |
Red Hat Enterprise Linux 6 (file) | RHSA-2014:1606 | 2014-10-13 |
Red Hat Software Collections 1 for Red Hat Enterprise Linux 7 (php55-php) | RHSA-2014:1766 | 2014-10-30 |
Red Hat Enterprise Linux 7 (php) | RHSA-2014:1013 | 2014-08-06 |
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 (php55-php) | RHSA-2014:1766 | 2014-10-30 |
Platform | Package | State |
---|---|---|
Red Hat Enterprise Linux 5 | file | Not affected |
Red Hat Enterprise Linux 5 | rpm | Not affected |
Red Hat Enterprise Linux 5 | cdrtools | Not affected |
Red Hat Enterprise Linux 5 | php | Not affected |