Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2014-8626 | First vendor Publication | 2014-11-22 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Stack-based buffer overflow in the date_from_ISO8601 function in ext/xmlrpc/libxmlrpc/xmlrpc.c in PHP before 5.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by including a timezone field in a date, leading to improper XML-RPC encoding. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8626 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:28186 | |||
Oval ID: | oval:org.mitre.oval:def:28186 | ||
Title: | RHSA-2014:1824 -- php security update (Important) | ||
Description: | PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. A buffer overflow flaw was found in the Exif extension. A specially crafted JPEG or TIFF file could cause a PHP application using the exif_thumbnail() function to crash or, possibly, execute arbitrary code with the privileges of the user running that PHP application. (CVE-2014-3670) A stack-based buffer overflow flaw was found in the way the xmlrpc extension parsed dates in the ISO 8601 format. A specially crafted XML-RPC request or response could possibly cause a PHP application to crash. (CVE-2014-8626) An integer overflow flaw was found in the way custom objects were unserialized. Specially crafted input processed by the unserialize() function could cause a PHP application to crash. (CVE-2014-3669) All php users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. After installing the updated packages, the httpd daemon must be restarted for the update to take effect. | ||
Family: | unix | Class: | patch |
Reference(s): | RHSA-2014:1824 CESA-2014:1824 CVE-2014-3669 CVE-2014-3670 CVE-2014-8626 | Version: | 3 |
Platform(s): | Red Hat Enterprise Linux 5 CentOS Linux 5 | Product(s): | php |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2014-11-10 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20141106_php_on_SL5_x.nasl - Type : ACT_GATHER_INFO |
2014-11-07 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2014-1824.nasl - Type : ACT_GATHER_INFO |
2014-11-07 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2014-1824.nasl - Type : ACT_GATHER_INFO |
2014-11-07 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2014-1824.nasl - Type : ACT_GATHER_INFO |
2008-12-05 | Name : The remote web server uses a version of PHP that is affected by multiple vuln... File : php_5_2_7.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 12:43:31 |
|
2024-08-02 12:30:15 |
|
2024-08-02 01:09:00 |
|
2024-02-02 01:29:21 |
|
2024-02-01 12:08:39 |
|
2023-11-07 21:45:09 |
|
2023-09-05 12:27:49 |
|
2023-09-05 01:08:31 |
|
2023-09-02 12:27:49 |
|
2023-09-02 01:08:40 |
|
2023-08-12 12:30:20 |
|
2023-08-12 01:08:08 |
|
2023-08-11 12:25:57 |
|
2023-08-11 01:08:21 |
|
2023-08-06 12:25:12 |
|
2023-08-06 01:08:07 |
|
2023-08-04 12:25:16 |
|
2023-08-04 01:08:11 |
|
2023-07-14 12:25:15 |
|
2023-07-14 01:08:10 |
|
2023-03-29 01:27:03 |
|
2023-03-28 12:08:30 |
|
2022-10-11 12:22:47 |
|
2022-10-11 01:08:18 |
|
2021-05-04 12:34:59 |
|
2021-04-22 01:42:32 |
|
2020-05-23 01:53:42 |
|
2020-05-23 00:42:46 |
|
2019-06-08 12:06:29 |
|
2018-10-03 12:04:30 |
|
2016-10-05 01:01:53 |
|
2016-06-29 00:41:57 |
|
2016-04-27 01:26:28 |
|
2015-04-30 09:27:21 |
|
2014-12-03 09:27:51 |
|
2014-11-24 21:26:42 |
|
2014-11-23 09:21:56 |
|