Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-4049

18
FAUCET Score

CVE-2014-4049 is a heap-based buffer overflow vulnerability in the php_parserr function of PHP versions 5.6.0beta4 and earlier, affecting Debian and OpenSUSE distributions. This flaw allows remote servers to trigger a denial of service or potentially execute arbitrary code through a specially crafted DNS TXT record when the dns_get_record function is used. With a CVSS score of 5.1, it has a network attack vector and high attack complexity, potentially leading to partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
11.3CPE matchmatch criteria
cpe:2.3:o:opensuse:opensuse:11.3:*:*:*:*:*:*:*
>= 5.3.0, < 5.3.29CPE matchmatch criteria
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
>= 5.4.0, < 5.4.30CPE matchmatch criteria
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
>= 5.5.0, < 5.5.14CPE matchmatch criteria
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
5.6.0CPE matchmatch criteria
cpe:2.3:a:php:php:5.6.0:alpha1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.1MEDIUM

AV:N/AC:H/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
HIGH
Authentication
NONE
Exploitability Score
4.9
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
10.91%
Probability of exploitation in next 30 days
EPSS Percentile
95.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1091 is in the 95th percentile among its peer group of 19,958 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (14)

github_advisorypatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: php-0:5.3.3-27.el6_5.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: php-0:5.4.16-23.el7_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections 1 for Red Hat Enterprise Linux 6Fixed in: php54-php-0:5.4.16-22.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections 1 for Red Hat Enterprise Linux 6Fixed in: php55-php-0:5.5.6-13.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUSFixed in: php54-php-0:5.4.16-22.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUSFixed in: php55-php-0:5.5.6-13.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: php53-0:5.3.3-23.el5_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.5 EUSFixed in: php55-php-0:5.5.6-13.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.6 EUSFixed in: php54-php-0:5.4.16-22.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.6 EUSFixed in: php55-php-0:5.5.6-13.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections 1 for Red Hat Enterprise Linux 7Fixed in: php54-php-0:5.4.16-22.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections 1 for Red Hat Enterprise Linux 7Fixed in: php55-php-0:5.5.6-13.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.5 EUSFixed in: php54-php-0:5.4.16-22.el6
View patch

Vendor Advisories (1)

redhatCVE-2014-4049Moderate

php: heap-based buffer overflow in DNS TXT record parsing

Jun 11, 2014

References

lists.apple.com / archives/security-announce/2015/Apr/msg00001.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2014-07/msg00001.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2014-07/msg00002.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-updates/2014-06/msg00051.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-updates/2014-07/msg00032.html
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
rhn.redhat.com / errata/RHSA-2014-1765.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2014-1766.html
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue Tracking
secunia.com / advisories/59270
Third Party Advisory
secunia.com / advisories/59329
Third Party Advisory
secunia.com / advisories/59418
Third Party Advisory
secunia.com / advisories/59496
Third Party Advisory
secunia.com / advisories/59513
Third Party Advisory
secunia.com / advisories/59652
Third Party Advisory
secunia.com / advisories/60998
Third Party Advisory
github.com / php/php-src/commit/b34d7849ed90ced9345f8ea1c59bc8d101c18468
PatchThird Party Advisory
support.apple.com / HT204659
Third Party Advisory
support.apple.com / kb/HT6443
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
debian.org / security/2014/dsa-2961
Third Party Advisory
openwall.com / lists/oss-security/2014/06/13/4
Mailing ListThird Party Advisory
oracle.com / technetwork/topics/security/bulletinjan2015-2370101.html
Third Party Advisory
securityfocus.com / bid/68007
Third Party AdvisoryVDB Entry
securitytracker.com / id/1030435
Third Party AdvisoryVDB Entry