PT-2014-1419 · Debian+3 · File+3
Published
2014-06-01
·
Updated
2024-06-15
·
CVE-2014-3538
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
file versions prior to 5.19
Description
The issue is related to multiple vulnerabilities in the file package of the Debian GNU/Linux operating system, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely, allowing attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during the processing of an awk rule. The vulnerability exists due to an incomplete fix for a previous issue.
Recommendations
For versions prior to 5.19, update to version 5.19 or later to resolve the issue. As a temporary workaround, consider restricting access to the file package to minimize the risk of exploitation. Avoid using the file package for processing untrusted files until the issue is resolved.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Centos
Red Hat
Ubuntu
File