CVE-2013-7345

Priority
Low
Description
The BEGIN regular expression in the awk script detector in
magic/Magdir/commands in file before 5.15 uses multiple wildcards with
unlimited repetitions, which allows context-dependent attackers to cause a
denial of service (CPU consumption) via a crafted ASCII file that triggers
a large amount of backtracking, as demonstrated via a file with many
newline characters.
References
Bugs
Notes
jdstrand> see regression fix in DSA-2873-2
mdeslaur> introduced in 5.05, but included in Debian specific patch
mdeslaur> in older releases.
mdeslaur> The fix for this issue was not complete, resulting in
mdeslaur> CVE-2014-3538. The proper fix in CVE-2014-3538 is intrusive.
Assigned-to
mdeslaur
Package
Source: file (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 10.04 LTS (Lucid Lynx):released (5.03-5ubuntu1.3)
Ubuntu 12.04 LTS (Precise Pangolin):released (5.09-2ubuntu0.4)
Ubuntu 13.10 (Saucy Salamander):released (5.11-2ubuntu4.3)
Ubuntu 14.04 LTS (Trusty Tahr):released (1:5.14-2ubuntu3.1)
Ubuntu 14.10 (Utopic Unicorn):not-affected (1:5.18-1ubuntu1)
Patches:
Vendor:http://www.debian.org/security/2014/dsa-2873
Upstream:https://github.com/file/file/commit/ef2329cf71acb59204dd981e2c6cce6c81fe467c
More Information

Valid XHTML 1.0 Strict

Updated: 2014-07-15 19:14:21 UTC (commit 8235)