CVE-2014-1943
Publication date 18 February 2014
Last updated 24 July 2024
Ubuntu priority
Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted indirect offset value in the magic of a file.
Status
Package | Ubuntu Release | Status |
---|---|---|
file | 13.10 saucy |
Fixed 5.11-2ubuntu4.1
|
12.10 quantal |
Fixed 5.11-2ubuntu0.1
|
|
12.04 LTS precise |
Fixed 5.09-2ubuntu0.2
|
|
10.04 LTS lucid |
Fixed 5.03-5ubuntu1.1
|
|
php5 | 13.10 saucy |
Fixed 5.5.3+dfsg-1ubuntu2.2
|
12.10 quantal |
Fixed 5.4.6-1ubuntu1.7
|
|
12.04 LTS precise |
Fixed 5.3.10-1ubuntu3.10
|
|
10.04 LTS lucid |
Fixed 5.3.2-1ubuntu4.23
|
Notes
mdeslaur
third file commit fixes memory leak test case: https://github.com/glensc/file/commit/f52ef08461a4bf0ab69a362d850e0397e0ab39a8
Patch details
Package | Patch details |
---|---|
file | |
php5 |
References
Related Ubuntu Security Notices (USN)
- USN-2126-1
- PHP vulnerabilities
- 3 March 2014
- USN-2123-1
- file vulnerabilities
- 26 February 2014