Buffer overflow in PHP - CVE-2014-3668
Published: November 27, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to buffer overflow in the date_from_ISO8601 function in the mkgmtime implementation in libxmlrpc/xmlrpc.c in the XMLRPC extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2. A remote attacker can trigger memory corruption via a crafted first argument to the xmlrpc_set_type function or (2) a crafted argument to the xmlrpc_decode function, related to an out-of-bounds read operation and cause the service to crash.
Affected software
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux EUS Compute Node
Slackware Linux
Fedora
php5 (Ubuntu package)
php
How to mitigate CVE-2014-3668
php5 (Ubuntu package) - addressed in versions 5.3.2-1ubuntu4.28, 5.3.10-1ubuntu3.15
php - update to 5.6.2-1.fc21