USN-2276-1
Dashboard / Vulnerabilities / USN-2276-1
USN-2276-1
Summary: php5 vulnerabilities
Details: Francisco Alonso discovered that the PHP Fileinfo component incorrectly handled certain CDF documents. A remote attacker could use this issue to cause PHP to hang or crash, resulting in a denial of service. (CVE-2014-0207, CVE-2014-3478, CVE-2014-3479, CVE-2014-3480, CVE-2014-3487) Stefan Esser discovered that PHP incorrectly handled unserializing SPL extension objects. An attacker could use this issue to execute arbitrary code. (CVE-2014-3515) It was discovered that PHP incorrectly handled certain SPL Iterators. An attacker could use this issue to cause PHP to crash, resulting in a denial of service. (CVE-2014-4670) It was discovered that PHP incorrectly handled certain ArrayIterators. An attacker could use this issue to cause PHP to crash, resulting in a denial of service. (CVE-2014-4698) Stefan Esser discovered that PHP incorrectly handled variable types when calling phpinfo(). An attacker could use this issue to possibly gain access to arbitrary memory, possibly containing sensitive information. (CVE-2014-4721)
References: https://ubuntu.com/security/notices/USN-2276-1, https://ubuntu.com/security/CVE-2014-0207, https://ubuntu.com/security/CVE-2014-3478, https://ubuntu.com/security/CVE-2014-3479, https://ubuntu.com/security/CVE-2014-3480, https://ubuntu.com/security/CVE-2014-3487, https://ubuntu.com/security/CVE-2014-3515, https://ubuntu.com/security/CVE-2014-4670, https://ubuntu.com/security/CVE-2014-4698, https://ubuntu.com/security/CVE-2014-4721
Affected packages
Package
Name: php5
Purl: pkg:deb/ubuntu/[email protected]+dfsg-1ubuntu4.3?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
