CVE-2014-8116 - Medium Severity Vulnerability
Vulnerable Library - php-srcphp-5.3.0alpha3
The PHP Interpreter
Library home page: https://github.com/php/php-src.git
Found in HEAD commit: b3a5f0a9284e14b3a029438cb818417b46cdb2ba
Found in base branch: PECL_OPENSSL
Vulnerable Source Files (1)
php-src/ext/fileinfo/libmagic/elfclass.h
Vulnerability Details
The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large number of (1) program or (2) section headers or (3) invalid capabilities.
Publish Date: 2014-12-17
URL: CVE-2014-8116
CVSS 3 Score Details (5.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: N/A
- Attack Complexity: N/A
- Privileges Required: N/A
- User Interaction: N/A
- Scope: N/A
- Impact Metrics:
- Confidentiality Impact: N/A
- Integrity Impact: N/A
- Availability Impact: N/A
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2014-8116
Release Date: 2014-12-17
Fix Resolution: 5.21
Step up your Open Source Security Game with WhiteSource here
CVE-2014-8116 - Medium Severity Vulnerability
The PHP Interpreter
Library home page: https://github.com/php/php-src.git
Found in HEAD commit: b3a5f0a9284e14b3a029438cb818417b46cdb2ba
Found in base branch: PECL_OPENSSL
The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large number of (1) program or (2) section headers or (3) invalid capabilities.
Publish Date: 2014-12-17
URL: CVE-2014-8116
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: N/A
- Attack Complexity: N/A
- Privileges Required: N/A
- User Interaction: N/A
- Scope: N/A
- Impact Metrics:
- Confidentiality Impact: N/A
- Integrity Impact: N/A
- Availability Impact: N/A
For more information on CVSS3 Scores, click here.Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2014-8116
Release Date: 2014-12-17
Fix Resolution: 5.21
Step up your Open Source Security Game with WhiteSource here