Skip to main content

PHP Fileinfo libmagic AWK File Processing Denial of Service Vulnerability

Last Update Date: 26 Mar 2014 18:53 Release Date: 26 Mar 2014 3822 Views

RISK: Medium Risk

TYPE: Servers - Internet App Servers

TYPE: Internet App Servers

A vulnerability has been identified in PHP, which can be exploited by malicious people to cause a DoS (Denial of Service).

 

The vulnerability is caused due to an error in the libmagic library bundled in the Fileinfo extension when processing certain AWK scripts, which can be exploited to cause excessive CPU resources consumption via a specially crafted AWK script file.


Impact

  • Denial of Service

System / Technologies affected

  • Versions 5.5.x and 5.4.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Fixed in the source code repository.

Vulnerability Identifier


Source


Related Link