CVE-2014-3538
php5 - security update
EPSS 11.8%
描述
file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7345.
如何修補 CVE-2014-3538
要修補 CVE-2014-3538,請將受影響套件升級到下列已修補版本。
- Debian/file—升級至 1:5.19-1 或更新版本
- Debian/file—升級至 5.04-5+squeeze7 或更新版本
- Debian/php5—升級至 5.3.3-7+squeeze22 或更新版本
- —升級至 5.4.4-14+deb7u13 或更新版本
CVE-2014-3538 正在被利用嗎?
中等 — EPSS 為 11.8%,可持續追蹤但非最高優先。
受影響套件(4)
- from 0, < 1:5.19-1
- from 0, < 5.04-5+squeeze7
- from 0, < 5.3.3-7+squeeze22
- from 0, < 5.4.4-14+deb7u13