5
CVSSv2

CVE-2014-9620

Published: 21/01/2015 Updated: 16/06/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The ELF parser in file 5.08 up to and including 5.21 allows remote malicious users to cause a denial of service via a large number of notes.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

file project file 5.14

file project file 5.15

file project file 5.08

file project file 5.09

file project file 5.16

file project file 5.17

file project file 5.12

file project file 5.13

file project file 5.20

file project file 5.21

file project file 5.10

file project file 5.11

file project file 5.18

file project file 5.19

Vendor Advisories

Several security issues were fixed in file ...
Multiple security issues have been found in file, a tool/library to determine a file type Processing a malformed file could result in denial of service Most of the changes are related to parsing ELF files As part of the fixes, several limits on aspects of the detection were added or tightened, sometimes resulting in messages like recursion limit ...
The ELF parser in file 508 through 521 allows remote attackers to cause a denial of service via a large number of notes (CVE-2014-9620) The ELF parser (readelfc) in file before 521 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large number of (1) program or (2) section headers or (3) invalid capabilities ...
A flaw was found in the way the File Information (fileinfo) extension parsed Executable and Linkable Format (ELF) files A remote attacker could use this flaw to crash a PHP application using fileinfo via a specially crafted ELF file ...