The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted CDF file.
Metrics
Affected Vendors & Products
References
History
Thu, 04 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 | |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published: 2014-07-09T10:00:00.000Z
Updated: 2025-12-04T20:29:06.728Z
Reserved: 2013-12-03T00:00:00.000Z
Link: CVE-2014-0207
Updated: 2024-08-06T09:05:39.204Z
Status : Deferred
Published: 2014-07-09T11:07:01.243
Modified: 2025-12-04T21:16:05.100
Link: CVE-2014-0207