Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The cdf_unpack_summary_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (performance degradation) by triggering many file_printf calls.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHP 资源管理错误漏洞
Vulnerability Description
PHP(PHP:Hypertext Preprocessor,PHP:超文本预处理器)是PHP Group和开放源代码社区共同维护的一种开源的通用计算机脚本语言。Fileinfo是其中的一个用于显示文件属性并支持批量修改其属性的组件。 PHP 5.3.28及之前的版本和5.5.13之前的5.5.x版本的Fileinfo组件的cdf.c文件中‘cdf_unpack_summary_info’函数存在安全漏洞。远程攻击者可借助特制的CDF文件利用该漏洞造成拒绝服务(无限循环)。
CVSS Information
N/A
Vulnerability Type
N/A