Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8117

Опубликовано: 16 дек. 2014
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors.

A flaw was found in the way the File Information (fileinfo) extension parsed Executable and Linkable Format (ELF) files. A remote attacker could use this flaw to cause a PHP application using fileinfo to consume an excessive amount of system resources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5fileWill not fix
Red Hat Enterprise Linux 5phpNot affected
Red Hat Enterprise Linux 5php53Not affected
Red Hat Enterprise Linux 6phpNot affected
Red Hat Enterprise Linux 7phpNot affected
Red Hat Software Collectionsphp54-phpNot affected
Red Hat Software Collectionsphp55-phpNot affected
Red Hat Software Collectionsrh-php56-phpNot affected
Red Hat Enterprise Linux 6fileFixedRHSA-2016:076010.05.2016
Red Hat Enterprise Linux 7fileFixedRHSA-2015:215519.11.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400->CWE-674
https://bugzilla.redhat.com/show_bug.cgi?id=1174606file: denial of service issue (resource consumption)

EPSS

Процентиль: 92%
0.09294
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors.

nvd
больше 10 лет назад

softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors.

debian
больше 10 лет назад

softmagic.c in file before 5.21 does not properly limit recursion, whi ...

github
около 3 лет назад

softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors.

fstec
больше 10 лет назад

Уязвимость операционной системы Gentoo Linux, позволяющая удаленному злоумышленнику нарушить доступность защищаемой информации

EPSS

Процентиль: 92%
0.09294
Низкий

4.3 Medium

CVSS2