Lucene search

K
cveRedhatCVE-2014-3669
HistoryOct 29, 2014 - 10:55 a.m.

CVE-2014-3669

2014-10-2910:55:03
CWE-189
redhat
web.nvd.nist.gov
168
cve
php
integer overflow
remote attackers
denial of service
arbitrary code
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

9.3

Confidence

High

EPSS

0.937

Percentile

99.1%

Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an argument to the unserialize function that triggers calculation of a large length value.

Affected configurations

Nvd
Node
phpphpRange5.4.33
OR
phpphpMatch5.4.0
OR
phpphpMatch5.4.1
OR
phpphpMatch5.4.2
OR
phpphpMatch5.4.3
OR
phpphpMatch5.4.4
OR
phpphpMatch5.4.5
OR
phpphpMatch5.4.6
OR
phpphpMatch5.4.7
OR
phpphpMatch5.4.8
OR
phpphpMatch5.4.9
OR
phpphpMatch5.4.10
OR
phpphpMatch5.4.11
OR
phpphpMatch5.4.12
OR
phpphpMatch5.4.12rc1
OR
phpphpMatch5.4.12rc2
OR
phpphpMatch5.4.13
OR
phpphpMatch5.4.13rc1
OR
phpphpMatch5.4.14
OR
phpphpMatch5.4.14rc1
OR
phpphpMatch5.4.15rc1
OR
phpphpMatch5.4.16rc1
OR
phpphpMatch5.4.17
OR
phpphpMatch5.4.18
OR
phpphpMatch5.4.19
OR
phpphpMatch5.4.20
OR
phpphpMatch5.4.21
OR
phpphpMatch5.4.22
OR
phpphpMatch5.4.23
OR
phpphpMatch5.4.24
OR
phpphpMatch5.4.25
OR
phpphpMatch5.4.26
OR
phpphpMatch5.4.27
OR
phpphpMatch5.4.28
OR
phpphpMatch5.4.29
OR
phpphpMatch5.4.30
OR
phpphpMatch5.4.31
OR
phpphpMatch5.4.32
OR
phpphpMatch5.5.0
OR
phpphpMatch5.5.0alpha1
OR
phpphpMatch5.5.0alpha2
OR
phpphpMatch5.5.0alpha3
OR
phpphpMatch5.5.0alpha4
OR
phpphpMatch5.5.0alpha5
OR
phpphpMatch5.5.0alpha6
OR
phpphpMatch5.5.0beta1
OR
phpphpMatch5.5.0beta2
OR
phpphpMatch5.5.0beta3
OR
phpphpMatch5.5.0beta4
OR
phpphpMatch5.5.0rc1
OR
phpphpMatch5.5.0rc2
OR
phpphpMatch5.5.1
OR
phpphpMatch5.5.2
OR
phpphpMatch5.5.3
OR
phpphpMatch5.5.4
OR
phpphpMatch5.5.5
OR
phpphpMatch5.5.6
OR
phpphpMatch5.5.7
OR
phpphpMatch5.5.8
OR
phpphpMatch5.5.9
OR
phpphpMatch5.5.10
OR
phpphpMatch5.5.11
OR
phpphpMatch5.5.12
OR
phpphpMatch5.5.13
OR
phpphpMatch5.5.14
OR
phpphpMatch5.5.15
OR
phpphpMatch5.5.16
OR
phpphpMatch5.5.17
OR
phpphpMatch5.6.0
OR
phpphpMatch5.6.1
VendorProductVersionCPE
phpphp*cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
phpphp5.4.0cpe:2.3:a:php:php:5.4.0:*:*:*:*:*:*:*
phpphp5.4.1cpe:2.3:a:php:php:5.4.1:*:*:*:*:*:*:*
phpphp5.4.2cpe:2.3:a:php:php:5.4.2:*:*:*:*:*:*:*
phpphp5.4.3cpe:2.3:a:php:php:5.4.3:*:*:*:*:*:*:*
phpphp5.4.4cpe:2.3:a:php:php:5.4.4:*:*:*:*:*:*:*
phpphp5.4.5cpe:2.3:a:php:php:5.4.5:*:*:*:*:*:*:*
phpphp5.4.6cpe:2.3:a:php:php:5.4.6:*:*:*:*:*:*:*
phpphp5.4.7cpe:2.3:a:php:php:5.4.7:*:*:*:*:*:*:*
phpphp5.4.8cpe:2.3:a:php:php:5.4.8:*:*:*:*:*:*:*
Rows per page:
1-10 of 701

References

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

9.3

Confidence

High

EPSS

0.937

Percentile

99.1%