CVE-2014-3479 is a denial-of-service vulnerability affecting the 'file' utility (before version 5.19) and the Fileinfo component in PHP (before 5.4.30 and 5.5.14). It arises from incorrect sector-size data handling in CDF file processing, allowing remote attackers to crash applications via a crafted stream offset. With a CVSS score of 4.3 (medium severity), it requires medium attack complexity and results in partial availability impact. There is no known active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.19CPE matchmatch criteria | cpe:2.3:a:file_project:file:*:*:*:*:*:*:*:* | ||
< 5.3.29CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
>= 5.4.0, < 5.4.30CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
>= 5.5.0, < 5.5.14CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.