A AegiFlow
MEDIUMCVSS 5.0

CVE-2014-3710

CVE-2014-3710 updated by NVD

Modified
2026-09-20
Sources
nvd

Summary

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

Affected packages

EcosystemPackageAffected versionsFixed versions
PHPphp[object Object], [object Object], [object Object]

References

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.