CVE-2014-3587: Christos Zoulas File

Medium severity, CVSS 4.3. EPSS: 20.2% chance of exploitation in the next 30 days.

Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1571.

Affected products

  • Christos Zoulas File: up to and including 5.19; version 5.00 only; version 5.01 only; version 5.02 only; version 5.03 only; version 5.04 only; …
  • PHP PHP: up to and including 5.4.31; version 5.4.0 only; version 5.4.1 only; version 5.4.2 only; version 5.4.3 only; version 5.4.4 only; …

Published 2014-08-23. Last modified 2026-06-17.