Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.1.2.2015.131
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DLA-131-1)
Summary:The remote host is missing an update for the Debian 'file' package(s) announced via the DLA-131-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'file' package(s) announced via the DLA-131-1 advisory.

Vulnerability Insight:
Multiple security issues have been found in file, a tool/library to determine a file type. Processing a malformed file could result in denial of service. Most of the changes are related to parsing ELF files.

As part of the fixes, several limits on aspects of the detection were added or tightened, sometimes resulting in messages like recursion limit exceeded or too many program header sections.

To mitigate such shortcomings, these limits are controllable by a new '-R'/'--recursion' parameter in the file program. Note: A future upgrade for file in squeeze-lts might replace this with the '-P' parameter to keep usage consistent across all distributions.

CVE-2014-8116

The ELF parser (readelf.c) allows remote attackers to cause a denial of service (CPU consumption or crash).

CVE-2014-8117

softmagic.c does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash).

(no identifier has been assigned so far)

out-of-bounds memory access

For Debian 6 Squeeze, these issues have been fixed in file version 5.04-5+squeeze9

Affected Software/OS:
'file' package(s) on Debian 6.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2014-8116
BugTraq ID: 71700
http://www.securityfocus.com/bid/71700
FreeBSD Security Advisory: FreeBSD-SA-14:28
https://www.freebsd.org/security/advisories/FreeBSD-SA-14:28.file.asc
http://seclists.org/oss-sec/2014/q4/1056
RedHat Security Advisories: RHSA-2016:0760
http://rhn.redhat.com/errata/RHSA-2016-0760.html
http://www.securitytracker.com/id/1031344
http://secunia.com/advisories/61944
http://secunia.com/advisories/62081
http://www.ubuntu.com/usn/USN-2494-1
Common Vulnerability Exposure (CVE) ID: CVE-2014-8117
BugTraq ID: 71692
http://www.securityfocus.com/bid/71692
http://www.ubuntu.com/usn/USN-2535-1
CopyrightCopyright (C) 2023 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.