IsItPatchedInstant security status for any software version
← All products

CVE-2014-3587

MEDIUM severity · CVSS 4.3 · CWE-189
4.3CVSS MEDIUM

Summary

Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1571.

Impact & exploitability

Attack vectorNetwork
Attack complexity
Privileges required
User interaction
Confidentiality impactNone
Integrity impactNone
Availability impact
Exploit probability (EPSS)30%

AV:N/AC:M/Au:N/C:N/I:N/A:P

Affected products we track (1)

PHP

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.

Last checked: Wed, 10 Jun 2026 22:18:30 UTC