PublicDateAtUSN: 2014-02-18 Candidate: CVE-2014-1943 PublicDate: 2014-02-18 19:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1943 http://mx.gw.com/pipermail/file/2014/001337.html http://www.debian.org/security/2014/dsa-2861 http://mx.gw.com/pipermail/file/2014/001334.html http://mx.gw.com/pipermail/file/2014/001330.html http://mx.gw.com/pipermail/file/2014/001327.html https://ubuntu.com/security/notices/USN-2123-1 https://ubuntu.com/security/notices/USN-2126-1 Description: Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted indirect offset value in the magic of a file. Ubuntu-Description: Notes: mdeslaur> third file commit fixes memory leak mdeslaur> test case: https://github.com/glensc/file/commit/f52ef08461a4bf0ab69a362d850e0397e0ab39a8 Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=739012 (php5) http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=738832 (file) Priority: medium Discovered-by: Bernd Melchers Assigned-to: CVSS: Patches_php5: upstream: http://git.php.net/?p=php-src.git;a=commitdiff;h=89f864c upstream: http://git.php.net/?p=php-src.git;a=commitdiff;h=10eb007 upstream_php5: needed lucid_php5: released (5.3.2-1ubuntu4.23) precise_php5: released (5.3.10-1ubuntu3.10) quantal_php5: released (5.4.6-1ubuntu1.7) saucy_php5: released (5.5.3+dfsg-1ubuntu2.2) devel_php5: released (5.5.9+dfsg-1ubuntu2) Patches_file: upstream: https://github.com/glensc/file/commit/4afb9b168906f117e32a11367761cd50fe9d4abe (backport) upstream: https://github.com/glensc/file/commit/3c081560c23f20b2985c285338b52c7aae9fdb0f upstream: https://github.com/glensc/file/commit/cc9e74dfeca5265ad725acc926ef0b8d2a18ee70 upstream: https://github.com/glensc/file/commit/c0c0032b9e9eb57b91fefef905a3b018bab492d9 upstream_file: released (5.17) lucid_file: released (5.03-5ubuntu1.1) precise_file: released (5.09-2ubuntu0.2) quantal_file: released (5.11-2ubuntu0.1) saucy_file: released (5.11-2ubuntu4.1) devel_file: released (1:5.14-2ubuntu2)