Описание
ELSA-2016-0760: file security, bug fix, and enhancement update (MODERATE)
[5.04-30]
- fix CVE-2014-3538 (unrestricted regular expression matching)
[5.04-29]
- fix #1284826 - try to read ELF header to detect corrupted one
[5.04-28]
- fix #1263987 - fix bugs found by coverity in the patch
[5.04-27]
- fix CVE-2014-3587 (incomplete fix for CVE-2012-1571)
- fix CVE-2014-3710 (out-of-bounds read in elf note headers)
- fix CVE-2014-8116 (multiple DoS issues (resource consumption))
- fix CVE-2014-8117 (denial of service issue (resource consumption))
- fix CVE-2014-9620 (limit the number of ELF notes processed)
- fix CVE-2014-9653 (malformed elf file causes access to uninitialized memory)
[5.04-26]
- fix #809898 - add support for detection of Python 2.7 byte-compiled files
[5.04-25]
- fix #1263987 - fix coredump execfn detection on ppc64 and s390
[5.04-24]
- fix #966953 - include msooxml file in magic.mgc generation
[5.04-23]
- fix #966953 - increate the strength of MSOOXML magic patterns
[5.04-22]
- fix #1169509 - add support for Java 1.7 and 1.8
- fix #1243650 - comment out too-sensitive Pascal magic
- fix #1080453 - remove .orig files from magic directory
- fix #1161058 - add support for EPUB
- fix #1162149 - remove parts of patches patching .orig files
- fix #1154802 - fix detection of zip files containing file named 'mime'
- fix #1246073 - fix detection UTF8 and UTF16 encoded XML files
- fix #1263987 - add new 'execfn' to coredump output to show the real name of executable which generated the coredump
- fix #809898 - add support for detection of Python 3.2-3.5 byte-compiled files
- fix #966953 - backport support for MSOOXML
Обновленные пакеты
Oracle Linux 6
Oracle Linux x86_64
file
5.04-30.el6
file-devel
5.04-30.el6
file-libs
5.04-30.el6
file-static
5.04-30.el6
python-magic
5.04-30.el6
Oracle Linux i686
file
5.04-30.el6
file-devel
5.04-30.el6
file-libs
5.04-30.el6
file-static
5.04-30.el6
python-magic
5.04-30.el6
Oracle Linux sparc64
file
5.04-30.el6
file-devel
5.04-30.el6
file-libs
5.04-30.el6
file-static
5.04-30.el6
python-magic
5.04-30.el6
Ссылки на источники
Связанные уязвимости
ELSA-2015-2155: file security and bug fix update (MODERATE)
The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.
The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.
The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.
The donote function in readelf.c in file through 5.20, as used in the ...