CVE-2014-3710: Canonical Ubuntu Linux
Medium severity, CVSS 5.0. EPSS: 14% chance of exploitation in the next 30 days.
The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.
Affected products
- Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 14.04 only; version 14.10 only
- Debian Debian Linux: version 7.0 only; version 8.0 only
- PHP PHP: from 5.4.0, before 5.4.35 (fixed in 5.4.35); from 5.5.0, before 5.5.19 (fixed in 5.5.19); from 5.6.0, before 5.6.3 (fixed in 5.6.3)
Published 2014-11-05. Last modified 2026-06-17.