Description
The cdf_read_property_info function in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate a stream offset, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file.
Remediation
References
Related Vulnerabilities
WordPress Plugin Login with phone number Security Bypass (1.7.26)
WordPress Plugin DB Toolkit 'uploadify.php' Arbitrary File Upload (0.1.10)
Django Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-0472)
Jboss EAP Server-Side Request Forgery (SSRF) Vulnerability (CVE-2018-14721)