CVE-2012-1571

Publication date 17 July 2012

Last updated 24 July 2024


Ubuntu priority

file before 5.11 and libmagic allow remote attackers to cause a denial of service (crash) via a crafted Composite Document File (CDF) file that triggers (1) an out-of-bounds read or (2) an invalid pointer dereference.

Read the notes from the security team

Status

Package Ubuntu Release Status

Notes


jdstrand

regression fix in DSA-2422-2

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details

References

Related Ubuntu Security Notices (USN)

    • USN-2123-1
    • file vulnerabilities
    • 26 February 2014

Other references