CVE-2014-3478
Publication date 9 July 2014
Last updated 8 December 2025
Ubuntu priority
Cvss 3 Severity Score
Description
Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (application crash) via a crafted Pascal string in a FILE_PSTRING conversion.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| file | 14.04 LTS trusty |
Fixed 1:5.14-2ubuntu3.1
|
| php5 | 14.04 LTS trusty |
Fixed 5.5.9+dfsg-1ubuntu4.3
|
Notes
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score |
|
| Attack vector | Network |
| Attack complexity | Low |
| Privileges required | None |
| User interaction | Required |
| Scope | Unchanged |
| Confidentiality | None |
| Integrity impact | None |
| Availability impact | High |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-2278-1
- file vulnerabilities
- 15 July 2014
- USN-2276-1
- PHP vulnerabilities
- 9 July 2014