CVE-2014-2270
Publication date 14 March 2014
Last updated 24 July 2024
Ubuntu priority
softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.
Status
Package | Ubuntu Release | Status |
---|---|---|
file | ||
php5 | ||
Notes
mdeslaur
see regression fix in DSA-2873-2 The regression in the debian package is caused by a fix for a different issue which does not seem to have a CVE number: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=703993 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742262 (file regression 1) https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742265 (file regression 2)
Patch details
Package | Patch details |
---|---|
file | |
php5 |
References
Related Ubuntu Security Notices (USN)
- USN-2163-1
- PHP vulnerability
- 7 April 2014
- USN-2162-1
- file vulnerability
- 7 April 2014