CVE-2014-1943

Publication date 18 February 2014

Last updated 24 July 2024


Ubuntu priority

Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted indirect offset value in the magic of a file.

Read the notes from the security team

Status

Package Ubuntu Release Status
file 13.10 saucy
Fixed 5.11-2ubuntu4.1
12.10 quantal
Fixed 5.11-2ubuntu0.1
12.04 LTS precise
Fixed 5.09-2ubuntu0.2
10.04 LTS lucid
Fixed 5.03-5ubuntu1.1
php5 13.10 saucy
Fixed 5.5.3+dfsg-1ubuntu2.2
12.10 quantal
Fixed 5.4.6-1ubuntu1.7
12.04 LTS precise
Fixed 5.3.10-1ubuntu3.10
10.04 LTS lucid
Fixed 5.3.2-1ubuntu4.23

Notes


mdeslaur

third file commit fixes memory leak test case: https://github.com/glensc/file/commit/f52ef08461a4bf0ab69a362d850e0397e0ab39a8

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
file
php5