PT-2014-1419 · Debian+3 · File+3

Published

2014-06-01

·

Updated

2024-06-15

·

CVE-2014-3538

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions file versions prior to 5.19
Description The issue is related to multiple vulnerabilities in the file package of the Debian GNU/Linux operating system, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely, allowing attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during the processing of an awk rule. The vulnerability exists due to an incomplete fix for a previous issue.
Recommendations For versions prior to 5.19, update to version 5.19 or later to resolve the issue. As a temporary workaround, consider restricting access to the file package to minimize the risk of exploitation. Avoid using the file package for processing untrusted files until the issue is resolved.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00374
BDU:2015-01282
CESA-2014_1327
CESA-2015_2155
CESA-2016_0760
CVE-2014-3538
DLA-50-1
DLA-67-1
DSA-3008-1
DSA-3021-1
MGASA-2014-0307
MGASA-2014-0324
OPENSUSE-SU-2024:10290-1
OPENSUSE-SU-2024:10344-1
OPENSUSE-SU-2024:11169-1
RHSA-2014:1327
RHSA-2014:1765
RHSA-2014:1766
RHSA-2014_1327
RHSA-2015:2155
RHSA-2015_2155
RHSA-2016:0760
RHSA-2016_0760
USN-2278-1

Affected Products

Centos
Red Hat
Ubuntu
File