{
  "threat_severity" : "Moderate",
  "public_date" : "2014-12-05T00:00:00Z",
  "bugzilla" : {
    "description" : "php: heap buffer overflow in enchant_broker_request_dict()",
    "id" : "1194737",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1194737"
  },
  "cvss" : {
    "cvss_base_score" : "4.3",
    "cvss_scoring_vector" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
    "status" : "verified"
  },
  "cwe" : "CWE-122",
  "details" : [ "Heap-based buffer overflow in the enchant_broker_request_dict function in ext/enchant/enchant.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allows remote attackers to execute arbitrary code via vectors that trigger creation of multiple dictionaries.", "A heap buffer overflow flaw was found in the enchant_broker_request_dict() function of PHP's enchant extension. A specially crafted tag input could possibly cause a PHP application to crash." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "release_date" : "2015-07-09T00:00:00Z",
    "advisory" : "RHSA-2015:1218",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6",
    "package" : "php-0:5.3.3-46.el6_6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2015-06-23T00:00:00Z",
    "advisory" : "RHSA-2015:1135",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "php-0:5.4.16-36.ael7b_1"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 6",
    "release_date" : "2015-06-04T00:00:00Z",
    "advisory" : "RHSA-2015:1053",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el6",
    "package" : "php55-0:2.0-1.el6"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 6",
    "release_date" : "2015-06-04T00:00:00Z",
    "advisory" : "RHSA-2015:1053",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el6",
    "package" : "php55-php-0:5.5.21-2.el6"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 6",
    "release_date" : "2015-06-04T00:00:00Z",
    "advisory" : "RHSA-2015:1066",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el6",
    "package" : "php54-0:2.0-1.el6"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 6",
    "release_date" : "2015-06-04T00:00:00Z",
    "advisory" : "RHSA-2015:1066",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el6",
    "package" : "php54-php-0:5.4.40-1.el6"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 6",
    "release_date" : "2015-06-04T00:00:00Z",
    "advisory" : "RHSA-2015:1066",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el6",
    "package" : "php54-php-pecl-zendopcache-0:7.0.4-3.el6"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS",
    "release_date" : "2015-06-04T00:00:00Z",
    "advisory" : "RHSA-2015:1053",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el6",
    "package" : "php55-0:2.0-1.el6"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS",
    "release_date" : "2015-06-04T00:00:00Z",
    "advisory" : "RHSA-2015:1053",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el6",
    "package" : "php55-php-0:5.5.21-2.el6"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS",
    "release_date" : "2015-06-04T00:00:00Z",
    "advisory" : "RHSA-2015:1066",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el6",
    "package" : "php54-0:2.0-1.el6"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS",
    "release_date" : "2015-06-04T00:00:00Z",
    "advisory" : "RHSA-2015:1066",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el6",
    "package" : "php54-php-0:5.4.40-1.el6"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS",
    "release_date" : "2015-06-04T00:00:00Z",
    "advisory" : "RHSA-2015:1066",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el6",
    "package" : "php54-php-pecl-zendopcache-0:7.0.4-3.el6"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS",
    "release_date" : "2015-06-04T00:00:00Z",
    "advisory" : "RHSA-2015:1053",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el6",
    "package" : "php55-0:2.0-1.el6"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS",
    "release_date" : "2015-06-04T00:00:00Z",
    "advisory" : "RHSA-2015:1053",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el6",
    "package" : "php55-php-0:5.5.21-2.el6"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS",
    "release_date" : "2015-06-04T00:00:00Z",
    "advisory" : "RHSA-2015:1066",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el6",
    "package" : "php54-0:2.0-1.el6"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS",
    "release_date" : "2015-06-04T00:00:00Z",
    "advisory" : "RHSA-2015:1066",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el6",
    "package" : "php54-php-0:5.4.40-1.el6"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS",
    "release_date" : "2015-06-04T00:00:00Z",
    "advisory" : "RHSA-2015:1066",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el6",
    "package" : "php54-php-pecl-zendopcache-0:7.0.4-3.el6"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 7",
    "release_date" : "2015-06-04T00:00:00Z",
    "advisory" : "RHSA-2015:1053",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el7",
    "package" : "php55-0:2.0-1.el7"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 7",
    "release_date" : "2015-06-04T00:00:00Z",
    "advisory" : "RHSA-2015:1053",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el7",
    "package" : "php55-php-0:5.5.21-2.el7"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 7",
    "release_date" : "2015-06-04T00:00:00Z",
    "advisory" : "RHSA-2015:1066",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el7",
    "package" : "php54-0:2.0-1.el7"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 7",
    "release_date" : "2015-06-04T00:00:00Z",
    "advisory" : "RHSA-2015:1066",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el7",
    "package" : "php54-php-0:5.4.40-1.el7"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 7",
    "release_date" : "2015-06-04T00:00:00Z",
    "advisory" : "RHSA-2015:1066",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el7",
    "package" : "php54-php-pecl-zendopcache-0:7.0.4-3.el7"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 5",
    "fix_state" : "Not affected",
    "package_name" : "php",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5"
  }, {
    "product_name" : "Red Hat Enterprise Linux 5",
    "fix_state" : "Will not fix",
    "package_name" : "php53",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5"
  }, {
    "product_name" : "Red Hat Software Collections",
    "fix_state" : "Affected",
    "package_name" : "php54-php",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:1"
  }, {
    "product_name" : "Red Hat Software Collections",
    "fix_state" : "Affected",
    "package_name" : "php55-php",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:1"
  }, {
    "product_name" : "Red Hat Software Collections",
    "fix_state" : "Not affected",
    "package_name" : "rh-php56-php",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2014-9705\nhttps://nvd.nist.gov/vuln/detail/CVE-2014-9705" ],
  "name" : "CVE-2014-9705",
  "csaw" : false
}