CVE-2014-4049 is a heap-based buffer overflow vulnerability in the php_parserr function of PHP versions 5.6.0beta4 and earlier, affecting Debian and OpenSUSE distributions. This flaw allows remote servers to trigger a denial of service or potentially execute arbitrary code through a specially crafted DNS TXT record when the dns_get_record function is used. With a CVSS score of 5.1, it has a network attack vector and high attack complexity, potentially leading to partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.3CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:11.3:*:*:*:*:*:*:* | ||
>= 5.3.0, < 5.3.29CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
>= 5.4.0, < 5.4.30CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
>= 5.5.0, < 5.5.14CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
5.6.0CPE matchmatch criteria | cpe:2.3:a:php:php:5.6.0:alpha1:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.