CVE-2014-3478
Publication date 9 July 2014
Last updated 8 December 2025
Ubuntu priority
Cvss 3 Severity Score
Description
Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (application crash) via a crafted Pascal string in a FILE_PSTRING conversion.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| file | 14.04 LTS trusty |
Fixed 1:5.14-2ubuntu3.1
|
| php5 | 14.04 LTS trusty |
Fixed 5.5.9+dfsg-1ubuntu4.3
|
Notes
Severity score breakdown
CVSS version: CVSS v3.0
Base score
6.5 · Medium
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
References
Related Ubuntu Security Notices (USN)
- USN-2278-1
- file vulnerabilities
- 15 July 2014
- USN-2276-1
- PHP vulnerabilities
- 9 July 2014