High severity7.3NVD Advisory· Published Dec 31, 2014· Updated Jun 17, 2026
CVE-2014-9426
CVE-2014-9426
Description
The apprentice_load function in libmagic/apprentice.c in the Fileinfo component in PHP through 5.6.4 attempts to perform a free operation on a stack-based character array, which allows remote attackers to cause a denial of service (memory corruption or application crash) or possibly have unspecified other impact via unknown vectors. NOTE: this is disputed by the vendor because the standard erealloc behavior makes the free operation unreachable
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- osv-coords3 versionspkg:rpm/opensuse/php5&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/php8&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/php7&distro=openSUSE%20Tumbleweed
< 5.6.28-1.1+ 2 more
- (no CPE)range: < 5.6.28-1.1
- (no CPE)range: < 8.0.11-1.1
- (no CPE)range: < 7.0.14-1.4
Patches
Vulnerability mechanics
References
4- bugs.php.net/bug.phpnvdVendor Advisory
- git.php.netnvd
- git.php.netnvd
- lists.opensuse.org/opensuse-updates/2015-02/msg00079.htmlnvd
News mentions
0No linked articles in our index yet.