DSA-2422-2 file -- missing bounds checks

Related Vulnerabilities: CVE-2012-1571  

The file type identification tool, file, and its associated library, libmagic, do not properly process malformed files in the Composite Document File (CDF) format, leading to crashes. Note that after this update, file may return different detection results for CDF files (well-formed or not). The new detections are believed to be more accurate. For the stable distribution (squeeze), this problem has been fixed in version 5.04-5+squeeze2. We recommend that you upgrade your file packages.

Debian Security Advisory

DSA-2422-2 file -- missing bounds checks

Date Reported:
09 May 2012
Affected Packages:
file
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2012-1571.
More information:

The file type identification tool, file, and its associated library, libmagic, do not properly process malformed files in the Composite Document File (CDF) format, leading to crashes.

Note that after this update, file may return different detection results for CDF files (well-formed or not). The new detections are believed to be more accurate.

For the stable distribution (squeeze), this problem has been fixed in version 5.04-5+squeeze2.

We recommend that you upgrade your file packages.