Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2014-8117

Published: 17 December 2014

softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors.

Priority

Low

Status

Package Release Status
file
Launchpad, Ubuntu, Debian
lucid
Released (5.03-5ubuntu1.5)
precise
Released (5.09-2ubuntu0.6)
trusty
Released (1:5.14-2ubuntu3.3)
upstream Needs triage

utopic
Released (1:5.19-1ubuntu1.2)
Patches:
upstream: https://github.com/file/file/commit/0de3251fe9fdeb00ec4c6d694d4d6709f202d1ee
upstream: https://github.com/file/file/commit/c0c0032b9e9eb57b91fefef905a3b018bab492d9
upstream: https://github.com/file/file/commit/6f737ddfadb596d7d4a993f7ed2141ffd664a81c
upstream: https://github.com/file/file/commit/90018fe22ff8b74a22fcd142225b0a00f3f12677
upstream: https://github.com/file/file/commit/5063ca3a2e00c5499789ccaa1ae2a41611377b77
upstream: https://github.com/file/file/commit/6bf45271eb8e0e6577b92042ce2003ba998d1686
php5
Launchpad, Ubuntu, Debian
lucid
Released (5.3.2-1ubuntu4.29)
precise
Released (5.3.10-1ubuntu3.17)
trusty
Released (5.5.9+dfsg-1ubuntu4.7)
upstream Needs triage

utopic
Released (5.5.12+dfsg-2ubuntu4.3)