PHP 'exif _ thumbnail () 'Function Heap Buffer Overflow (CVE-2014-3670)
Release date:
Updated on:
Affected Systems:
PHP
Unaffected system:
PHP 5.x
Description:
Bugtraq id: 70665
CVE (CAN) ID: CVE-2014-3670
PHP is a widely used scripting language. It is especially suitable for Web development and can be embedded into HTML.
PHP has a boundary error in the implementation of the "date_from_ISO8601 ()" function (ext/xmlrpc/libxmlrpc/xmlrpc. c). Attackers can exploit this vulnerability to read out-of-bounds memory.
<* Source: Otto Ebeling
Link: http://secunia.com/advisories/61159/
*>
Suggestion:
Vendor patch:
PHP
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.php.net/downloads.php
PHP:
Http://php.net/ChangeLog-5.php#5.6.2
Http://php.net/ChangeLog-5.php#5.5.18
Http://php.net/ChangeLog-5.php#5.4.34
Http://bugs.php.net/68113
Symeon Paraschoudis:
Http://bugs.php.net/68044
Http://bugs.php.net/68027
Install LNMP in CentOS 6.3 (PHP 5.4, MyySQL5.6)
Nginx startup failure occurs during LNMP deployment.
Ubuntu install Nginx php5-fpm MySQL (LNMP environment setup)
Detailed php hd scanning PDF + CD source code + full set of teaching videos
PHP details: click here
PHP: click here
This article permanently updates the link address: