CVE-2013-7345

Priority
Low
Description
The BEGIN regular expression in the awk script detector in
magic/Magdir/commands in file before 5.15 uses multiple wildcards with
unlimited repetitions, which allows context-dependent attackers to cause a
denial of service (CPU consumption) via a crafted ASCII file that triggers
a large amount of backtracking, as demonstrated via a file with many
newline characters.
References
Bugs
Notes
 jdstrand> see regression fix in DSA-2873-2
 mdeslaur> introduced in 5.05, but included in Debian specific patch
 mdeslaur> in older releases.
 mdeslaur> The fix for this issue was not complete, resulting in
 mdeslaur> CVE-2014-3538. The proper fix in CVE-2014-3538 is intrusive.
Assigned-to
mdeslaur
Package
Source: file (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 12.04 LTS (Precise Pangolin):released (5.09-2ubuntu0.4)
Ubuntu 14.04 LTS (Trusty Tahr):released (1:5.14-2ubuntu3.1)
Patches:
Vendor:http://www.debian.org/security/2014/dsa-2873
Upstream:https://github.com/file/file/commit/ef2329cf71acb59204dd981e2c6cce6c81fe467c
More Information

Valid XHTML 1.0 Strict

Updated: 2015-07-29 20:42:11 UTC (commit 9756)