Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-2270

Опубликовано: 20 дек. 2013
Источник: redhat
CVSS2: 4.3

Описание

softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.

A denial of service flaw was found in the way the File Information (fileinfo) extension handled search rules. A remote attacker could use this flaw to cause a PHP application using fileinfo to crash or consume an excessive amount of CPU.

Отчет

This issue did not affect the php packages as shipped with Red Hat Enterprise Linux 5. This issue did not affect the php packages as shipped with Red Hat Enterprise Linux 7.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5cdrtoolsWill not fix
Red Hat Enterprise Linux 5fileAffected
Red Hat Enterprise Linux 5phpNot affected
Red Hat Enterprise Linux 5rpmWill not fix
Red Hat Enterprise Linux 7fileNot affected
Red Hat Enterprise Linux 7phpNot affected
Red Hat Software Collectionsphp55-phpAffected
Red Hat Enterprise Linux 5php53FixedRHSA-2014:101206.08.2014
Red Hat Enterprise Linux 6phpFixedRHSA-2014:101206.08.2014
Red Hat Enterprise Linux 6fileFixedRHSA-2014:160613.10.2014

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190->CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1072220file: out-of-bounds access in search rules with offsets from input file

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.

nvd
больше 11 лет назад

softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.

debian
больше 11 лет назад

softmagic.c in file before 5.17 and libmagic allows context-dependent ...

github
около 3 лет назад

softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.

oracle-oval
больше 10 лет назад

ELSA-2014-1606: file security and bug fix update (MODERATE)

4.3 Medium

CVSS2