VID |
22641 |
Severity |
40 |
Port |
80, ... |
Protocol |
TCP |
Class |
CGI |
Detailed Description |
According to its banner, the version of PHP 5.4.x installed on the remote host is a version prior to 5.4.35. It is, therefore, affected by the following vulnerability :
- out-of-bounds read error in the function 'donote' within the file 'ext/fileinfo/libmagic/readelf.c' that could allow application crashes.
* Note: This check solely relied on the version number of the remote PHP to assess this vulnerability, so this might be a false positive.
* References: http://php.net/ChangeLog-5.php#5.4.35 https://bugs.php.net/bug.php?id=68283
* Platforms Affected: PHP Prior to 5.4.35 Any operating system Any version |
Recommendation |
Upgrade to the latest version of PHP (5.4.35 or later), available from the PHP web site at http://www.php.net/downloads.php |
Related URL |
CVE-2014-3710 (CVE) |
Related URL |
70807 (SecurityFocus) |
Related URL |
(ISS) |
|