{
  "threat_severity" : "Moderate",
  "public_date" : "2014-06-27T00:00:00Z",
  "bugzilla" : {
    "description" : "file: cdf_count_chain insufficient boundary check",
    "id" : "1104858",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1104858"
  },
  "cvss" : {
    "cvss_base_score" : "4.3",
    "cvss_scoring_vector" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
    "status" : "verified"
  },
  "details" : [ "The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file.", "A denial of service flaw was found in the way the File Information (fileinfo) extension parsed certain Composite Document Format (CDF) files. A remote attacker could use this flaw to crash a PHP application using fileinfo via a specially crafted CDF file." ],
  "statement" : "This issue did not affect the php and the file packages as shipped with Red Hat Enterprise Linux 5.\nThis issue affects the versions of file as shipped with Red Hat Enterprise Linux 7. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.",
  "acknowledgement" : "This issue was discovered by Francisco Alonso (Red Hat Product Security).",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 5",
    "release_date" : "2014-08-06T00:00:00Z",
    "advisory" : "RHSA-2014:1012",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5",
    "package" : "php53-0:5.3.3-23.el5_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "release_date" : "2014-08-06T00:00:00Z",
    "advisory" : "RHSA-2014:1012",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6",
    "package" : "php-0:5.3.3-27.el6_5.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "release_date" : "2014-10-13T00:00:00Z",
    "advisory" : "RHSA-2014:1606",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6",
    "package" : "file-0:5.04-21.el6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2014-08-06T00:00:00Z",
    "advisory" : "RHSA-2014:1013",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "php-0:5.4.16-23.el7_0"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2015-11-19T00:00:00Z",
    "advisory" : "RHSA-2015:2155",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "file-0:5.11-31.el7"
  }, {
    "product_name" : "Red Hat Software Collections 1 for Red Hat Enterprise Linux 6",
    "release_date" : "2014-10-30T00:00:00Z",
    "advisory" : "RHSA-2014:1765",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:1::el6",
    "package" : "php54-php-0:5.4.16-22.el6"
  }, {
    "product_name" : "Red Hat Software Collections 1 for Red Hat Enterprise Linux 6",
    "release_date" : "2014-10-30T00:00:00Z",
    "advisory" : "RHSA-2014:1766",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:1::el6",
    "package" : "php55-php-0:5.5.6-13.el6"
  }, {
    "product_name" : "Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUS",
    "release_date" : "2014-10-30T00:00:00Z",
    "advisory" : "RHSA-2014:1765",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:1::el6",
    "package" : "php54-php-0:5.4.16-22.el6"
  }, {
    "product_name" : "Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUS",
    "release_date" : "2014-10-30T00:00:00Z",
    "advisory" : "RHSA-2014:1766",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:1::el6",
    "package" : "php55-php-0:5.5.6-13.el6"
  }, {
    "product_name" : "Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.5 EUS",
    "release_date" : "2014-10-30T00:00:00Z",
    "advisory" : "RHSA-2014:1765",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:1::el6",
    "package" : "php54-php-0:5.4.16-22.el6"
  }, {
    "product_name" : "Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.5 EUS",
    "release_date" : "2014-10-30T00:00:00Z",
    "advisory" : "RHSA-2014:1766",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:1::el6",
    "package" : "php55-php-0:5.5.6-13.el6"
  }, {
    "product_name" : "Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.6 EUS",
    "release_date" : "2014-10-30T00:00:00Z",
    "advisory" : "RHSA-2014:1765",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:1::el6",
    "package" : "php54-php-0:5.4.16-22.el6"
  }, {
    "product_name" : "Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.6 EUS",
    "release_date" : "2014-10-30T00:00:00Z",
    "advisory" : "RHSA-2014:1766",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:1::el6",
    "package" : "php55-php-0:5.5.6-13.el6"
  }, {
    "product_name" : "Red Hat Software Collections 1 for Red Hat Enterprise Linux 7",
    "release_date" : "2014-10-30T00:00:00Z",
    "advisory" : "RHSA-2014:1765",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:1::el7",
    "package" : "php54-php-0:5.4.16-22.el7"
  }, {
    "product_name" : "Red Hat Software Collections 1 for Red Hat Enterprise Linux 7",
    "release_date" : "2014-10-30T00:00:00Z",
    "advisory" : "RHSA-2014:1766",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:1::el7",
    "package" : "php55-php-0:5.5.6-13.el7"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 5",
    "fix_state" : "Not affected",
    "package_name" : "cdrtools",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5"
  }, {
    "product_name" : "Red Hat Enterprise Linux 5",
    "fix_state" : "Not affected",
    "package_name" : "file",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5"
  }, {
    "product_name" : "Red Hat Enterprise Linux 5",
    "fix_state" : "Not affected",
    "package_name" : "php",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5"
  }, {
    "product_name" : "Red Hat Enterprise Linux 5",
    "fix_state" : "Not affected",
    "package_name" : "rpm",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2014-3480\nhttps://nvd.nist.gov/vuln/detail/CVE-2014-3480" ],
  "name" : "CVE-2014-3480",
  "csaw" : false
}