PHP Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability - CVE-2014-9652 - Vulnerability Database

PHP Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability - CVE-2014-9652

Medium
Reference: CVE-2014-9652
Title: PHP Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Overview:

The mconvert function in softmagic.c in file before 5.21 as used in the Fileinfo component in PHP before 5.4.37 5.5.x before 5.5.21 and 5.6.x before 5.6.5 does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file.