CVE-2014-3487
EPSS 14.5%
Description
The cdf_read_property_info function in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate a stream offset, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file.
How to fix CVE-2014-3487
To remediate CVE-2014-3487, upgrade the affected package to a fixed version below.
- Debian/file—upgrade to 1:5.19-1 or later
Is CVE-2014-3487 being exploited?
Moderate — EPSS is 14.5%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 1:5.19-1