Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-3538

Опубликовано: 03 июл. 2014
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5

Описание

file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7345.

РелизСтатусПримечание
devel

released

1:5.19-1ubuntu1
esm-infra-legacy/trusty

not-affected

1:5.14-2ubuntu3.1
lucid

ignored

precise

released

5.09-2ubuntu0.4
saucy

released

5.11-2ubuntu4.3
trusty

released

1:5.14-2ubuntu3.1
trusty/esm

not-affected

1:5.14-2ubuntu3.1
upstream

released

1:5.19-1

Показывать по

EPSS

Процентиль: 90%
0.05532
Низкий

5 Medium

CVSS2

Связанные уязвимости

redhat
почти 11 лет назад

file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7345.

nvd
почти 11 лет назад

file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7345.

debian
почти 11 лет назад

file before 5.19 does not properly restrict the amount of data read du ...

github
около 3 лет назад

file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7345.

fstec
почти 11 лет назад

Уязвимость программного обеспечения PHP, позволяющая удаленному злоумышленнику нарушить доступность защищаемой информации

EPSS

Процентиль: 90%
0.05532
Низкий

5 Medium

CVSS2