CVE-2014-9705

Publication date 31 December 2014

Last updated 24 July 2024


Ubuntu priority

Heap-based buffer overflow in the enchant_broker_request_dict function in ext/enchant/enchant.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allows remote attackers to execute arbitrary code via vectors that trigger creation of multiple dictionaries.

Status

Package Ubuntu Release Status
php5 14.10 utopic
Fixed 5.5.12+dfsg-2ubuntu4.3
14.04 LTS trusty
Fixed 5.5.9+dfsg-1ubuntu4.7
12.04 LTS precise
Fixed 5.3.10-1ubuntu3.17
10.04 LTS lucid
Fixed 5.3.2-1ubuntu4.29

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
php5

References

Related Ubuntu Security Notices (USN)

Other references