Lucene search

K
osvGoogleOSV:DSA-3072-1
HistoryNov 11, 2014 - 12:00 a.m.

file - security update

2014-11-1100:00:00
Google
osv.dev
12

0.063 Low

EPSS

Percentile

93.6%

Francisco Alonso of Red Hat Product Security found an issue in the file
utility: when checking ELF files, note headers are incorrectly checked,
thus potentially allowing attackers to cause a denial of service
(out-of-bounds read and application crash) by supplying a specially
crafted ELF file.

For the stable distribution (wheezy), this problem has been fixed in
version 5.11-2+deb7u6.

For the upcoming stable distribution (jessie), this problem will be
fixed soon.

For the unstable distribution (sid), this problem has been fixed in
version 1:5.20-2.

We recommend that you upgrade your file packages.