The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted CDF file.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-0018-1 | php5 security update |
![]() |
DLA-27-1 | file security update |
![]() |
DSA-2974-1 | php5 security update |
![]() |
DSA-3021-1 | file security update |
![]() |
DSA-3021-2 | file regression update |
![]() |
USN-2276-1 | PHP vulnerabilities |
![]() |
USN-2278-1 | file vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T09:05:39.204Z
Reserved: 2013-12-03T00:00:00
Link: CVE-2014-0207

No data.

Status : Deferred
Published: 2014-07-09T11:07:01.243
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-0207


No data.