Vulnerability Database

296,213

Total vulnerabilities in the database

CVE-2013-4636

The mget function in libmagic/softmagic.c in the Fileinfo component in PHP 5.4.x before 5.4.16 allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via an MP3 file that triggers incorrect MIME type detection during access to an finfo object.

  • Published: Jun 21, 2013
  • Updated: Apr 13, 2023
  • CVE: CVE-2013-4636
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:N/A:P

CWEs:

Software From Fixed in
php / php 5.4.12 5.4.12.x
php / php 5.4.15 5.4.15.x
php / php 5.4.14 5.4.14.x
php / php 5.4.8 5.4.8.x
php / php 5.4.9 5.4.9.x
php / php 5.4.11 5.4.11.x
php / php 5.4.10 5.4.10.x
php / php 5.4.2 5.4.2.x
php / php 5.4.5 5.4.5.x
php / php 5.4.6 5.4.6.x
php / php 5.4.13 5.4.13.x
php / php 5.4.0 5.4.0.x
php / php 5.4.3 5.4.3.x
php / php 5.4.1 5.4.1.x
php / php 5.4.7 5.4.7.x
php / php 5.4.4 5.4.4.x