Input validation error in PHP - CVE-2013-4636

 

Input validation error in PHP - CVE-2013-4636

Published: June 22, 2013 / Updated: August 11, 2020


Vulnerability identifier: #VU42773
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-4636
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

The mget function in libmagic/softmagic.c in the Fileinfo component in PHP 5.4.x before 5.4.16 allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via an MP3 file that triggers incorrect MIME type detection during access to an finfo object.


Affected software

PHP
Gentoo Linux
dev-lang/php

How to mitigate CVE-2013-4636

Install update from vendor's website.

dev-lang/php - update to 5.5.16

External References

Related Security Bulletins