Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1571.
Vector
NETWORK
Complexity
MEDIUM
Authentication
NONE
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL
PHP 5.5.0 release candidate 1
PHP 5.5.0 beta4
PHP 5.5.0 beta3
PHP 5.5.0 beta2
PHP 5.5.0 beta1
PHP 5.5.0 alpha6
PHP 5.5.0 alpha5
PHP 5.5.0 alpha4
PHP 5.5.0 alpha3
PHP 5.5.0 alpha2
PHP 5.5.0 alpha1
PHP 5.5.0
Php Php 5.4.31 (not an official CPE)
PHP 5.4.30
PHP 5.4.29
PHP 5.4.28
PHP 5.4.27
PHP 5.4.26
PHP 5.4.25
PHP 5.4.24
PHP 5.4.23
PHP 5.4.22
PHP 5.4.21
PHP 5.4.20
PHP 5.4.19
PHP 5.4.18
PHP 5.4.17
PHP 5.4.16 release candidate 1
PHP 5.4.15 release candidate 1
Php Php 5.4.15 (not an official CPE)
PHP 5.4.14 release candidate 1
PHP 5.4.14
PHP 5.4.13 release candidate 1
PHP 5.4.13
PHP 5.4.12 release candidate 2
PHP 5.4.12 release candidate 1
PHP 5.4.12
PHP 5.4.11
PHP 5.4.10
PHP 5.4.9
PHP 5.4.8
PHP 5.4.7
PHP 5.4.6
PHP 5.4.5
PHP 5.4.4
PHP 5.4.3
PHP 5.4.2
PHP 5.4.1
Php Php 5.4.0 Rc2 (not an official CPE)
Php Php 5.4.0 Beta2 32-bit (not an official CPE)
Php Php 5.4.0 Beta2 (not an official CPE)
PHP 5.4.0
Christos Zoulas file 5.19
Christos Zoulas file 5.18
Christos Zoulas file 5.17
Christos Zoulas file 5.16
Christos Zoulas file 5.15
Christos Zoulas file 5.14
Christos Zoulas file 5.13
Christos Zoulas file 5.12
Christos Zoulas file 5.11
Christos Zoulas file 5.10
PHP 5.5.0 release candidate 2
Christos Zoulas file 5.09
Christos Zoulas file 5.08
Christos Zoulas file 5.07
Christos Zoulas file 5.06
Christos Zoulas file 5.05
Christos Zoulas file 5.04
Christos Zoulas file 5.03
Christos Zoulas file 5.02
Christos Zoulas file 5.01
Christos Zoulas file 5.00
PHP 5.5.1
PHP 5.5.2
PHP 5.5.3
PHP 5.5.4
PHP 5.5.5
PHP 5.5.6
PHP 5.5.7
PHP 5.5.8
PHP 5.5.9
PHP 5.5.10
PHP 5.5.11
PHP 5.5.12
PHP 5.5.13
PHP 5.5.14
Php Php 5.5.15 (not an official CPE)