CVE-2014-9426
Published: 31 December 2014
** DISPUTED ** The apprentice_load function in libmagic/apprentice.c in the Fileinfo component in PHP through 5.6.4 attempts to perform a free operation on a stack-based character array, which allows remote attackers to cause a denial of service (memory corruption or application crash) or possibly have unspecified other impact via unknown vectors. NOTE: this is disputed by the vendor because the standard erealloc behavior makes the free operation unreachable.
Notes
Author | Note |
---|---|
mdeslaur | this CVE has been disputed as it isn't exploitable. |
Priority
Status
Package | Release | Status |
---|---|---|
php5 Launchpad, Ubuntu, Debian |
upstream |
Needs triage
|
lucid |
Not vulnerable
|
|
precise |
Not vulnerable
|
|
trusty |
Not vulnerable
|
|
utopic |
Not vulnerable
|
|
vivid |
Not vulnerable
|
|
file Launchpad, Ubuntu, Debian |
upstream |
Needs triage
|
lucid |
Not vulnerable
|
|
precise |
Not vulnerable
|
|
trusty |
Not vulnerable
|
|
utopic |
Not vulnerable
|
|
vivid |
Not vulnerable
|