PHP Improper Input Validation Vulnerability - CVE-2014-9653 - Vulnerability Database

PHP Improper Input Validation Vulnerability - CVE-2014-9653

High
Reference: CVE-2014-9653
Title: PHP Improper Input Validation Vulnerability
Overview:

readelf.c in file before 5.22 as used in the Fileinfo component in PHP before 5.4.37 5.5.x before 5.5.21 and 5.6.x before 5.6.5 does not consider that pread calls sometimes read only a subset of the available data which allows remote attackers to cause a denial of service (uninitialized memory access) or possibly have unspecified other impact via a crafted ELF file.