CVE-2014-4049

PHP < 5.3.29 - Heap-Based Buffer Overflow via DNS TXT Record Parsing

Title source: llm
STIX 2.1

Description

Heap-based buffer overflow in the php_parserr function in ext/standard/dns.c in PHP 5.6.0beta4 and earlier allows remote servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS TXT record, related to the dns_get_record function.

References (25)

Core 25
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59329
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2014-07/msg00001.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59418
Third Party Advisory x_refsource_confirm
https://support.apple.com/HT204659
Third Party Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21683486
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59496
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1030435
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-1766.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59652
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/68007
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59513
Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141017844705317&w=2
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2014-07/msg00002.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60998
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59270
Mailing List, Third Party Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html
Third Party Advisory x_refsource_confirm
http://support.apple.com/kb/HT6443
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2014-06/msg00051.html
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1108447
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2014/dsa-2961
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-1765.html
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/06/13/4
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2014-07/msg00032.html

Scores

EPSS 0.3067
EPSS Percentile 96.8%

Details

CWE
CWE-119
Status published
Products (5)
debian/debian_linux 7.0
debian/debian_linux 8.0
opensuse/opensuse 11.3
php/php 5.6.0 alpha1 (8 CPE variants)
php/php 5.3.0 - 5.3.29
Published Jun 18, 2014
Tracked Since Feb 18, 2026