Summary: | <sys-apps/file-5.21: out of bounds read in mconvert() | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | base-system |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://bugs.gw.com/view.php?id=398 | ||
See Also: |
http://bugs.gw.com/view.php?id=398 https://bugzilla.redhat.com/show_bug.cgi?id=1188599 |
||
Whiteboard: | A3 [glsa cve] | ||
Package list: | Runtime testing required: | --- |
Description
Agostino Sarubbo
2015-02-03 11:57:38 UTC
CVE-2014-9652 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9652): The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file. 5.22 is stable for everyone now @ Security: Waiting for GLSA... This issue was resolved and addressed in GLSA 201701-42 at https://security.gentoo.org/glsa/201701-42 by GLSA coordinator Aaron Bauman (b-man). |