PT-2014-1423 · File+6 · File+6

Francisco Alonso

+1

·

Published

2014-06-01

·

Updated

2025-12-04

·

CVE-2014-3480

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions file versions prior to 5.19 Red Hat Enterprise Linux file-static-5.04 Red Hat Enterprise Linux file-5.04 Red Hat Enterprise Linux file-debuginfo-5.04 Red Hat Enterprise Linux file-libs-5.04 Red Hat Enterprise Linux file-devel-5.04 Debian GNU/Linux file
Description The issue is related to multiple vulnerabilities in the file package, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely. The cdf count chain function in cdf.c does not properly validate sector-count data, allowing remote attackers to cause a denial of service via a crafted CDF file.
Recommendations For file versions prior to 5.19, update to version 5.19 or later. For Red Hat Enterprise Linux file-static-5.04, file-5.04, file-debuginfo-5.04, file-libs-5.04, and file-devel-5.04, update to a version that is not affected by these vulnerabilities. For Debian GNU/Linux file, update to a version that is not affected by these vulnerabilities. As a temporary workaround, consider restricting access to the cdf count chain function in cdf.c until a patch is available.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2505
ALT-PU-2023-1892
BDU:2015-00378
BDU:2015-01282
BDU:2015-06092
BDU:2015-06093
BDU:2015-06094
BDU:2015-06095
BDU:2015-06096
CESA-2014_1012
CESA-2014_1013
CESA-2014_1606
CESA-2015_2155
CVE-2014-3480
DLA-0018-1
DLA-27-1
DSA-2974-1
DSA-3021-1
HPSBUX03102
MGASA-2014-0282
MGASA-2014-0283
MGASA-2014-0284
RHSA-2014:1012
RHSA-2014:1013
RHSA-2014:1606
RHSA-2014:1765
RHSA-2014:1766
RHSA-2014_1012
RHSA-2014_1013
RHSA-2014_1606
RHSA-2015:2155
RHSA-2015_2155
SUSE-SU-2015:0370-1
SUSE-SU-2015:0436-1
SUSE-SU-2015:1018-1
SUSE-SU-2015:1265-1
SUSE-SU-2016:1638-1
USN-2276-1
USN-2278-1

Affected Products

Alt Linux
Centos
Hp-Ux
Red Hat
Suse
Ubuntu
File