5
CVSSv2

CVE-2014-1943

Published: 18/02/2014 Updated: 31/10/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Fine Free file prior to 5.17 allows context-dependent malicious users to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted indirect offset value in the magic of a file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fine free file project fine free file

php php

canonical ubuntu linux 13.10

canonical ubuntu linux 12.10

canonical ubuntu linux 10.04

canonical ubuntu linux 12.04

debian debian linux 7.0

debian debian linux 6.0

Vendor Advisories

Debian Bug report logs - #738832 Segmentation fault in libmagic (src:file) [CVE-2014-1943] Package: file; Maintainer for file is Christoph Biedl <debianaxhn@manchmalin-ulmde>; Source for file is src:file (PTS, buildd, popcon) Reported by: Christoph Biedl <debianaxhn@manchmalin-ulmde> Date: Thu, 13 Feb 2014 10:3 ...
It was discovered that file, a file type classification tool, contains a flaw in the handling of indirect magic rules in the libmagic library, which leads to an infinite recursion when trying to determine the file type of certain files The Common Vulnerabilities and Exposures project ID CVE-2014-1943 has been assigned to identify this flaw Additi ...
File could be made to crash if it processed a specially crafted file ...
Several security issues were fixed in PHP ...
A denial of service flaw was found in the way the File Information (fileinfo) extension handled indirect rules A remote attacker could use this flaw to cause a PHP application using fileinfo to crash or consume an excessive amount of CPU ...
Fine Free file before 517 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted indirect offset value in the magic of a file ...
A denial of service flaw was found in the way the File Information (fileinfo) extension handled indirect rules A remote attacker could use this flaw to cause a PHP application using fileinfo to crash or consume an excessive amount of CPU The gdImageCrop function in ext/gd/gdc in PHP 55x before 559 does not check return values, which allows ...
A denial of service flaw was found in the way the File Information (fileinfo) extension handled indirect rules A remote attacker could use this flaw to cause a PHP application using fileinfo to crash or consume an excessive amount of CPU ...