Sploitus

CVE-2014-3668

1 known exploit for CVE-2014-3668

Buffer overflow in the date_from_ISO8601 function in the mkgmtime implementation in libxmlrpc/xmlrpc.c in the XMLRPC extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) via (1) a crafted first argument to the xmlrpc_set_type function or (2) a crafted argument to the xmlrpc_decode function, related to an out-of-bounds read operation.

Affected products
Centos, Php, Red Hat, Suse, Ubuntu, Libxmlrpc
Php
≤ 5.4.33, 5.4.0, 5.4.1, 5.4.2, 5.4.3, 5.4.4, 5.4.5, 5.4.6, 5.4.7, 5.4.8, 5.4.9, 5.4.10, 5.4.11, 5.4.12, 5.4.13, 5.4.14, 5.4.15, 5.4.16, 5.4.17, 5.4.18, 5.4.19, 5.4.20, 5.4.21, 5.4.22, 5.4.23, 5.4.24, 5.4.25, 5.4.26, 5.4.27, 5.4.28, 5.4.29, 5.4.30, 5.4.31, 5.4.32, 5.5.0, 5.5.1, 5.5.2, 5.5.3, 5.5.4, 5.5.5
Fix
Available
CVSS 2.0
5.0 MEDIUM
EPSS
27.0% (98th percentile)
Weakness
CWE-119
NVD status
Modified
Published
2014-10-29
CVE-2014-3668 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2014-3668

Proof-of-concept code and exploit modules indexed by Sploitus