CVE-2014-9912
The get_icu_disp_value_src_php function in ext/intl/locale/locale_methods.c in PHP before 5.3.29, 5.4.x before 5.4.30, and 5.5.x before 5.5.14 does not properly restrict calls to the ICU uresbund.cpp component, which allows remote attackers to cause a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.95%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The get_icu_disp_value_src_php function in ext/intl/locale/locale_methods.c in PHP before 5.3.29, 5.4.x before 5.4.30, and 5.5.x before 5.5.14 does not properly restrict calls to the ICU uresbund.cpp component, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a locale_get_display_name call with a long first argument.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.95% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- php/php
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2016/11/25/1Third Party Advisory
- http://www.php.net/ChangeLog-5.phpRelease Notes, Vendor Advisory
- http://www.securityfocus.com/bid/68549
- https://bugs.php.net/bug.php?id=67397Patch, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1383569Issue Tracking, Patch, Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2016/11/25/1Third Party Advisory
- http://www.php.net/ChangeLog-5.phpRelease Notes, Vendor Advisory
- http://www.securityfocus.com/bid/68549
- https://bugs.php.net/bug.php?id=67397Patch, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1383569Issue Tracking, Patch, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.