![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.1.1.2.2015.131 |
Category: | Debian Local Security Checks |
Title: | Debian: Security Advisory (DLA-131-1) |
Summary: | The remote host is missing an update for the Debian 'file' package(s) announced via the DLA-131-1 advisory. |
Description: | Summary: The remote host is missing an update for the Debian 'file' package(s) announced via the DLA-131-1 advisory. Vulnerability Insight: Multiple security issues have been found in file, a tool/library to determine a file type. Processing a malformed file could result in denial of service. Most of the changes are related to parsing ELF files. As part of the fixes, several limits on aspects of the detection were added or tightened, sometimes resulting in messages like recursion limit exceeded or too many program header sections. To mitigate such shortcomings, these limits are controllable by a new '-R'/'--recursion' parameter in the file program. Note: A future upgrade for file in squeeze-lts might replace this with the '-P' parameter to keep usage consistent across all distributions. CVE-2014-8116 The ELF parser (readelf.c) allows remote attackers to cause a denial of service (CPU consumption or crash). CVE-2014-8117 softmagic.c does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash). (no identifier has been assigned so far) out-of-bounds memory access For Debian 6 Squeeze, these issues have been fixed in file version 5.04-5+squeeze9 Affected Software/OS: 'file' package(s) on Debian 6. Solution: Please install the updated package(s). CVSS Score: 5.0 CVSS Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2014-8116 BugTraq ID: 71700 http://www.securityfocus.com/bid/71700 FreeBSD Security Advisory: FreeBSD-SA-14:28 https://www.freebsd.org/security/advisories/FreeBSD-SA-14:28.file.asc http://seclists.org/oss-sec/2014/q4/1056 RedHat Security Advisories: RHSA-2016:0760 http://rhn.redhat.com/errata/RHSA-2016-0760.html http://www.securitytracker.com/id/1031344 http://secunia.com/advisories/61944 http://secunia.com/advisories/62081 http://www.ubuntu.com/usn/USN-2494-1 Common Vulnerability Exposure (CVE) ID: CVE-2014-8117 BugTraq ID: 71692 http://www.securityfocus.com/bid/71692 http://www.ubuntu.com/usn/USN-2535-1 |
Copyright | Copyright (C) 2023 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |