Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8117

Опубликовано: 16 дек. 2014
Источник: redhat
CVSS2: 4.3
EPSS Средний

Описание

softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors.

A flaw was found in the way the File Information (fileinfo) extension parsed Executable and Linkable Format (ELF) files. A remote attacker could use this flaw to cause a PHP application using fileinfo to consume an excessive amount of system resources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5fileWill not fix
Red Hat Enterprise Linux 5phpNot affected
Red Hat Enterprise Linux 5php53Not affected
Red Hat Enterprise Linux 6phpNot affected
Red Hat Enterprise Linux 7phpNot affected
Red Hat Software Collectionsphp54-phpNot affected
Red Hat Software Collectionsphp55-phpNot affected
Red Hat Software Collectionsrh-php56-phpNot affected
Red Hat Enterprise Linux 6fileFixedRHSA-2016:076010.05.2016
Red Hat Enterprise Linux 7fileFixedRHSA-2015:215519.11.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400->CWE-674
https://bugzilla.redhat.com/show_bug.cgi?id=1174606file: denial of service issue (resource consumption)

EPSS

Процентиль: 94%
0.14617
Средний

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors.

nvd
почти 11 лет назад

softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors.

debian
почти 11 лет назад

softmagic.c in file before 5.21 does not properly limit recursion, whi ...

github
больше 3 лет назад

softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors.

fstec
почти 11 лет назад

Уязвимость операционной системы Gentoo Linux, позволяющая удаленному злоумышленнику нарушить доступность защищаемой информации

EPSS

Процентиль: 94%
0.14617
Средний

4.3 Medium

CVSS2