CVE-2014-4670

Use-after-free vulnerability in ext/spl/spl_dllist.c in the SPL component in PHP through 5.5.14 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact via crafted iterator usage within applications in certain web-hosting environments.
References
Link Resource
http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html
http://lists.opensuse.org/opensuse-updates/2014-07/msg00035.html
http://lists.opensuse.org/opensuse-updates/2014-09/msg00046.html
http://rhn.redhat.com/errata/RHSA-2014-1326.html
http://rhn.redhat.com/errata/RHSA-2014-1327.html
http://rhn.redhat.com/errata/RHSA-2014-1765.html
http://rhn.redhat.com/errata/RHSA-2014-1766.html
http://secunia.com/advisories/54553
http://secunia.com/advisories/59831
http://secunia.com/advisories/60696
http://www-01.ibm.com/support/docview.wss?uid=swg21683486
http://www.debian.org/security/2014/dsa-3008
http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
https://bugs.php.net/bug.php?id=67538
https://support.apple.com/HT204659
http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html
http://lists.opensuse.org/opensuse-updates/2014-07/msg00035.html
http://lists.opensuse.org/opensuse-updates/2014-09/msg00046.html
http://rhn.redhat.com/errata/RHSA-2014-1326.html
http://rhn.redhat.com/errata/RHSA-2014-1327.html
http://rhn.redhat.com/errata/RHSA-2014-1765.html
http://rhn.redhat.com/errata/RHSA-2014-1766.html
http://secunia.com/advisories/54553
http://secunia.com/advisories/59831
http://secunia.com/advisories/60696
http://www-01.ibm.com/support/docview.wss?uid=swg21683486
http://www.debian.org/security/2014/dsa-3008
http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
https://bugs.php.net/bug.php?id=67538
https://support.apple.com/HT204659
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:alpha4:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:alpha5:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:alpha6:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:beta1:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:beta2:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:beta3:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:beta4:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:rc1:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:rc2:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.1:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.2:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.3:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.4:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.5:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.6:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.7:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.8:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.9:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.10:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.11:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.12:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.13:*:*:*:*:*:*:*

History

21 Nov 2024, 02:10

Type Values Removed Values Added
References () http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html - () http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html -
References () http://lists.opensuse.org/opensuse-updates/2014-07/msg00035.html - () http://lists.opensuse.org/opensuse-updates/2014-07/msg00035.html -
References () http://lists.opensuse.org/opensuse-updates/2014-09/msg00046.html - () http://lists.opensuse.org/opensuse-updates/2014-09/msg00046.html -
References () http://rhn.redhat.com/errata/RHSA-2014-1326.html - () http://rhn.redhat.com/errata/RHSA-2014-1326.html -
References () http://rhn.redhat.com/errata/RHSA-2014-1327.html - () http://rhn.redhat.com/errata/RHSA-2014-1327.html -
References () http://rhn.redhat.com/errata/RHSA-2014-1765.html - () http://rhn.redhat.com/errata/RHSA-2014-1765.html -
References () http://rhn.redhat.com/errata/RHSA-2014-1766.html - () http://rhn.redhat.com/errata/RHSA-2014-1766.html -
References () http://secunia.com/advisories/54553 - () http://secunia.com/advisories/54553 -
References () http://secunia.com/advisories/59831 - () http://secunia.com/advisories/59831 -
References () http://secunia.com/advisories/60696 - () http://secunia.com/advisories/60696 -
References () http://www-01.ibm.com/support/docview.wss?uid=swg21683486 - () http://www-01.ibm.com/support/docview.wss?uid=swg21683486 -
References () http://www.debian.org/security/2014/dsa-3008 - () http://www.debian.org/security/2014/dsa-3008 -
References () http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html - () http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html -
References () https://bugs.php.net/bug.php?id=67538 - () https://bugs.php.net/bug.php?id=67538 -
References () https://support.apple.com/HT204659 - () https://support.apple.com/HT204659 -

Information

Published : 2014-07-10 11:06

Updated : 2024-11-21 02:10


NVD link : CVE-2014-4670

Mitre link : CVE-2014-4670

CVE.ORG link : CVE-2014-4670


JSON object : View

Products Affected

php

  • php