Release date:
Updated on:
Affected Systems:
PHP 5.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 66002
CVE (CAN) ID: CVE-2014-2270
PHP is an embedded HTML language.
The PHP file program has the memory corruption vulnerability in parsing and porting the file in the execution body (PE) format, attackers can exploit this vulnerability to execute arbitrary code or cause denial-of-service attacks.
<* Source: vendor
Link: https://bugzilla.redhat.com/show_bug.cgi? CVE-2014-2270
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PHP
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.php.net/downloads.php
Http://bugs.gw.com/view.php? Id = 313
Https://github.com/glensc/file/commit/447558595a3650db2886cd2f416ad0beba965801