The mget function in libmagic/softmagic.c in the Fileinfo component in PHP 5.4.x before 5.4.16 allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via an MP3 file that triggers incorrect MIME type detection during access to an finfo object.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-lang/php. | Oct 30, 2017 | Jun 21, 2013 |
| Oracle Solaris | — | Upgrade web/php-52 to version 5.2.17-0.175.1.17.0.3.0 on Solaris 11.1Upgrade web/php-53 to version 5.3.27-0.175.1.17.0.3.0 on Solaris 11.1 | May 29, 2017 | Jun 21, 2013 |
| Php | — | Upgrade to PHP version 5.4.16 | Jul 11, 2013 | Jun 21, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub