UBUNTU-CVE-2014-9912
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-9912
UBUNTU-CVE-2014-9912
Summary:
Details: The get_icu_disp_value_src_php function in ext/intl/locale/locale_methods.c in PHP before 5.3.29, 5.4.x before 5.4.30, and 5.5.x before 5.5.14 does not properly restrict calls to the ICU uresbund.cpp component, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a locale_get_display_name call with a long first argument.
References: https://ubuntu.com/security/CVE-2014-9912, https://marc.info/?l=oss-security&m=148003512008712&w=2, https://ubuntu.com/security/notices/USN-3196-1, https://www.cve.org/CVERecord?id=CVE-2014-9912
Affected packages
Package
Name: php5
Purl: pkg:deb/ubuntu/[email protected]+dfsg-1ubuntu4.21?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
