Summary: | <sys-apps/file-5.22: malformed elf file causes access to uninitialized memory | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | base-system |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://bugs.gw.com/view.php?id=409 | ||
See Also: |
http://bugs.gw.com/view.php?id=409 https://bugzilla.redhat.com/show_bug.cgi?id=1190116 |
||
Whiteboard: | A3 [glsa cve] | ||
Package list: | Runtime testing required: | --- |
Description
Agostino Sarubbo
2015-02-06 13:56:53 UTC
CVE-2014-9653 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9653): readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory access) or possibly have unspecified other impact via a crafted ELF file. 5.22 is stable everywhere now @ Security: Waiting for GLSA... This issue was resolved and addressed in GLSA 201701-42 at https://security.gentoo.org/glsa/201701-42 by GLSA coordinator Aaron Bauman (b-man). |