sapi/cgi/cgi_main.c in the CGI component in PHP through 5.4.36, 5.5.x through 5.5.20, and 5.6.x through 5.6.4, when mmap is used to read a .php file, does not properly consider the mapping's length during processing of an invalid file that begins with a # character and lacks a newline character, which causes an out-of-bounds read and might (1) allow remote attackers to obtain sensitive information from php-cgi process memory by leveraging the ability to upload a .php file or (2) trigger unexpected code execution if a valid PHP script is present in memory locations adjacent to the mapping.
No CVSS v3.1
No CVSS v3.0
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial
AV:N/AC:L/Au:N/C:P/I:P/A:P
Vendors | Products |
---|---|
Php |
|
Configuration 1 [-]
|
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: debian
Published: 2015-01-03T02:00:00
Updated: 2016-12-29T18:57:01
Reserved: 2014-12-31T00:00:00
Link: CVE-2014-9427
JSON object: View
NVD Information
Status : Modified
Published: 2015-01-03T02:59:00.050
Modified: 2023-11-07T02:23:05.237
Link: CVE-2014-9427
JSON object: View
Redhat Information
No data.
CWE