Description
The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file.
Remediation
References
Related Vulnerabilities
WordPress Plugin Admin Custom Login Cross-Site Scripting (2.5.3.1)
Joomla! Core 2.5.x Information Disclosure (2.5.0 - 2.5.9)
Apache Traffic Server Remote DOS Attack (CVE-2021-27737)
WordPress Plugin Related YouTube Videos Cross-Site Request Forgery (1.9.8)
PHP Resource Management Errors Vulnerability (CVE-2007-4660)