From ${URL} : Out of bounds memory read was reported in file utility [1], which also affects PHP fileinfo module. Upstream fix that resolves this for file utility: https://github.com/file/file/commit/59e63838913eee47f5c120a6c53d4565af638158 PHP upstream fix: https://github.com/php/php-src/commit/ede59c8feb4b80e1b94e4abdaa0711051e2912ab [1]: http://bugs.gw.com/view.php?id=398 @maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
CVE-2014-9652 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9652): The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file.
5.22 is stable for everyone now
@ Security: Waiting for GLSA...
This issue was resolved and addressed in GLSA 201701-42 at https://security.gentoo.org/glsa/201701-42 by GLSA coordinator Aaron Bauman (b-man).