CVE-2014-0207 (retired)

Priority
Description
The cdf_read_short_sector function in cdf.c in file before 5.19, as used in
the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows
remote attackers to cause a denial of service (assertion failure and
application exit) via a crafted CDF file.
Notes
 sarnold> The php5 patch has only the security fix, prefer it for file as well
Assigned-to
mdeslaur
Package
Source: file (LP Ubuntu Debian)
Upstream:released (1:5.19-1)
Ubuntu 14.04 LTS (Trusty Tahr):released (1:5.14-2ubuntu3.1)
Patches:
Upstream:https://github.com/file/file/commit/6d209c1c489457397a5763bca4b28e43aac90391
More Information

Updated: 2019-03-26 12:12:07 UTC (commit ccdecfcf0fead22bd291e5f4ea745a46872dcb15)