The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP prior to 5.4.29 and 5.5.x prior to 5.5.13 allows remote malicious users to cause a denial of service (infinite loop or out-of-bounds memory access) via a vector that (1) has zero length or (2) is too long.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
php php |
||
debian debian linux 8.0 |
||
debian debian linux 7.0 |