CVE-2012-1571
published 2012-07-17CVE-2012-1571: file before 5.11 and libmagic allow remote attackers to cause a denial of service (crash) via a crafted Composite Document File (CDF) file that triggers (1) an…
PriorityP424medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
4.12%
89.7th percentile
file before 5.11 and libmagic allow remote attackers to cause a denial of service (crash) via a crafted Composite Document File (CDF) file that triggers (1) an out-of-bounds read or (2) an invalid pointer dereference.
Affected
79 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| christos_zoulas | file | <= 5.10 | — |
| christos_zoulas | file | <= 5.19 | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| debian | file | < file 5.11-1 (bookworm) | file 5.11-1 (bookworm) |
| debian | file | < file 1:5.19-2 (bookworm) | file 1:5.19-2 (bookworm) |
| file_project | file | >= 0 < 5.11-1 | 5.11-1 |
| file_project | file | >= 0 < 1:5.19-2 | 1:5.19-2 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xv4r-r9fj-hh6h: file before 5
ghsa_unreviewed·2022-05-17
CVE-2012-1571 [MEDIUM] CWE-119 GHSA-xv4r-r9fj-hh6h: file before 5
file before 5.11 and libmagic allow remote attackers to cause a denial of service (crash) via a crafted Composite Document File (CDF) file that triggers (1) an out-of-bounds read or (2) an invalid pointer dereference.
GHSA
GHSA-5mp5-8xxq-j3vx: Integer overflow in the cdf_read_property_info function in cdf
ghsa_unreviewed·2022-05-14·CVSS 6.5
CVE-2014-3587 [MEDIUM] GHSA-5mp5-8xxq-j3vx: Integer overflow in the cdf_read_property_info function in cdf
Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1571.
OSV
CVE-2014-3587: Integer overflow in the cdf_read_property_info function in cdf
osv·2014-08-23·CVSS 6.5
CVE-2014-3587 [MEDIUM] CVE-2014-3587: Integer overflow in the cdf_read_property_info function in cdf
Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1571.
OSV
CVE-2012-1571: file before 5
osv·2012-07-17·CVSS 6.5
CVE-2012-1571 [MEDIUM] CVE-2012-1571: file before 5
file before 5.11 and libmagic allow remote attackers to cause a denial of service (crash) via a crafted Composite Document File (CDF) file that triggers (1) an out-of-bounds read or (2) an invalid pointer dereference.
Red Hat
file: incomplete fix for CVE-2012-1571 in cdf_read_property_info
vendor_redhat·2014-08-21·CVSS 6.5
CVE-2014-3587 [MEDIUM] CWE-190 file: incomplete fix for CVE-2012-1571 in cdf_read_property_info
file: incomplete fix for CVE-2012-1571 in cdf_read_property_info
Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1571.
It was found that the fix for CVE-2012-1571 was incomplete; the File Information (fileinfo) extension did not correctly parse certain Composite Document Format (CDF) files. A remote attacker could use this flaw to crash a PHP application using fileinfo via a specially crafted CDF file.
Statement: This issue did not affect the php and the file packages as shipped with Red Hat Enterprise
BSD
FreeBSD-SA-14:16.file: Multiple vulnerabilities in file(1) and libmagic(3)
bsd_advisories·2014-06-24·CVSS 6.5
CVE-2012-1571 [MEDIUM] FreeBSD-SA-14:16.file: Multiple vulnerabilities in file(1) and libmagic(3)
FreeBSD-SA-14:16.file Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities in file(1) and libmagic(3)
Category: contrib
Module: file
Announced: 2014-06-24
Affects: All supported versions of FreeBSD.
Corrected: 2014-06-24 19:04:55 UTC (stable/10, 10.0-STABLE)
2014-06-24 19:05:08 UTC (releng/10.0, 10.0-RELEASE-p6)
2014-06-24 19:04:55 UTC (stable/9, 9.3-PRERELEASE)
2014-06-24 19:05:19 UTC (releng/9.3, 9.3-RC2)
2014-06-24 19:05:36 UTC (releng/9.2, 9.2-RELEASE-p9)
2014-06-24 19:05:36 UTC (releng/9.1, 9.1-RELEASE-p16)
2014-06-24 19:04:55 UTC (stable/8, 8.4-STABLE)
2014-06-24 19:05:47 UTC (releng/8.4, 8.4-RELEASE-p13)
CVE Name: CVE-2012-1571, CVE-2013-7345, CVE-2014-1943, CVE-2014-2270
For general information regarding FreeBSD Security Advisories,
including descriptions of the
Ubuntu
file vulnerabilities
vendor_ubuntu·2014-02-26·CVSS 6.5
CVE-2012-1571 [MEDIUM] file vulnerabilities
Title: file vulnerabilities
Summary: File could be made to crash if it processed a specially crafted file.
It was discovered that file incorrectly handled Composite Document files.
An attacker could use this issue to cause file to crash, resulting in a
denial of service. This issue only affected Ubuntu 10.04 LTS and Ubuntu
12.04 LTS. (CVE-2012-1571)
Bernd Melchers discovered that file incorrectly handled indirect offset
values. An attacker could use this issue to cause file to consume resources
or crash, resulting in a denial of service. (CVE-2014-1943)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2014-3587: file - Integer overflow in the cdf_read_property_info function in cdf.c in file through...
vendor_debian·2014·CVSS 6.5
CVE-2014-3587 [MEDIUM] CVE-2014-3587: file - Integer overflow in the cdf_read_property_info function in cdf.c in file through...
Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1571.
Scope: local
bookworm: resolved (fixed in 1:5.19-2)
bullseye: resolved (fixed in 1:5.19-2)
forky: resolved (fixed in 1:5.19-2)
sid: resolved (fixed in 1:5.19-2)
trixie: resolved (fixed in 1:5.19-2)
Red Hat
file: out of bounds read in CDF parser
vendor_redhat·2012-02-16·CVSS 6.5
CVE-2012-1571 [MEDIUM] CWE-122 file: out of bounds read in CDF parser
file: out of bounds read in CDF parser
file before 5.11 and libmagic allow remote attackers to cause a denial of service (crash) via a crafted Composite Document File (CDF) file that triggers (1) an out-of-bounds read or (2) an invalid pointer dereference.
A denial of service flaw was found in the way the File Information (fileinfo) extension parsed certain Composite Document Format (CDF) files. A remote attacker could use this flaw to crash a PHP application using fileinfo via a specially crafted CDF file.
Statement: This issue did not affect the versions of the php and file packages as shipped with Red Hat Enterprise Linux 5 and 7.
Package: cdrtools (Red Hat Enterprise Linux 5) - Not affected
Package: file (Red Hat Enterprise Linux 5) - Not affected
Package: php (Red Hat Enterprise
Debian
CVE-2012-1571: file - file before 5.11 and libmagic allow remote attackers to cause a denial of servic...
vendor_debian·2012·CVSS 6.5
CVE-2012-1571 [MEDIUM] CVE-2012-1571: file - file before 5.11 and libmagic allow remote attackers to cause a denial of servic...
file before 5.11 and libmagic allow remote attackers to cause a denial of service (crash) via a crafted Composite Document File (CDF) file that triggers (1) an out-of-bounds read or (2) an invalid pointer dereference.
Scope: local
bookworm: resolved (fixed in 5.11-1)
bullseye: resolved (fixed in 5.11-1)
forky: resolved (fixed in 5.11-1)
sid: resolved (fixed in 5.11-1)
trixie: resolved (fixed in 5.11-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3587 php: file: incomplete fix for CVE-2012-1571 in cdf_read_property_info [fedora-all]
bugzilla·2014-08-22·CVSS 6.5
CVE-2014-3587 [MEDIUM] CVE-2014-3587 php: file: incomplete fix for CVE-2012-1571 in cdf_read_property_info [fedora-all]
CVE-2014-3587 php: file: incomplete fix for CVE-2012-1571 in cdf_read_property_info [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple sup
Bugzilla
CVE-2014-3587 file: incomplete fix for CVE-2012-1571 in cdf_read_property_info [fedora-all]
bugzilla·2014-08-22·CVSS 6.5
CVE-2014-3587 [MEDIUM] CVE-2014-3587 file: incomplete fix for CVE-2012-1571 in cdf_read_property_info [fedora-all]
CVE-2014-3587 file: incomplete fix for CVE-2012-1571 in cdf_read_property_info [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
Bugzilla
CVE-2014-3587 file: incomplete fix for CVE-2012-1571 in cdf_read_property_info
bugzilla·2014-08-11·CVSS 6.5
CVE-2014-3587 [MEDIUM] CVE-2014-3587 file: incomplete fix for CVE-2012-1571 in cdf_read_property_info
CVE-2014-3587 file: incomplete fix for CVE-2012-1571 in cdf_read_property_info
A flaw was found in the way file uses cdf_read_property_info function when checks stream offsets for certain Composite Document Format (CDF).An insufficient input validation flaw for p and q minimal and maximal value, leads to a pointer overflow.This issue only affects 32bit systems.
771 cdf_read_property_info(const cdf_stream_t *sst, const cdf_header_t *h
..
835 q = (const uint8_t *)(const void *)
836 ((const char *)(const void *)p + ofs
837 - 2 * sizeof(uint32_t));
838 if (q > e) {
839 DPRINTF(("Ran of the end %p > %p\n", q, e));
840 goto out;
841 }
Upstream commit:
https://github.com/file/file/commit/0641e56be1af003aa02c7c6b0184466540637233
Discussion:
This issue is public:
http://lwn.net/Vulnerabilitie
Bugzilla
CVE-2012-1571 file: out of bounds read in CDF parser [fedora-all]
bugzilla·2014-06-30·CVSS 6.5
CVE-2012-1571 [MEDIUM] CVE-2012-1571 file: out of bounds read in CDF parser [fedora-all]
CVE-2012-1571 file: out of bounds read in CDF parser [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2014-0207 file: cdf_read_short_sector insufficient boundary check
bugzilla·2014-04-28·CVSS 6.5
CVE-2014-0207 [MEDIUM] CVE-2014-0207 file: cdf_read_short_sector insufficient boundary check
CVE-2014-0207 file: cdf_read_short_sector insufficient boundary check
Invalid pointer dereference flaws were found in the way file, utility for determining of file types processed header section for certain Composite Document Format (CDF) files. A remote attacker could provide a specially-crafted CDF file,
which once inspected by the file utility of the victim would lead to file executable crash.
Discussion:
This CVE was assigned to an incorrect boundary check in the cdf_read_short_sector() function. The issue was corrected as part of this upstream commit:
https://github.com/file/file/commit/6d209c1c489457397a5763bca4b28e43aac90391#diff-0
The boundary check was added as part of the CVE-2012-1571 fix (see bug 805197). The CVE-2014-0207 is really an incomplete / insufficient CVE-2012-15
Bugzilla
CVE-2012-1571 file: out of bounds read in CDF parser
bugzilla·2012-03-20·CVSS 6.5
CVE-2012-1571 [MEDIUM] CVE-2012-1571 file: out of bounds read in CDF parser
CVE-2012-1571 file: out of bounds read in CDF parser
Multiple out-of heap-based buffer read flaws and invalid pointer dereference flaws were found in the way file, utility for determining of file types processed header section for certain Composite Document Format (CDF) files. A remote attacker could provide a specially-crafted CDF file, which once inspected by the file utility of the victim would lead to file executable crash.
Upstream patches:
https://github.com/file/file/commit/1859fdb4e67c49c463c4e0078054335cd46ba295
https://github.com/file/file/commit/1140872578eedaeecf828f1841d17ff574372dba
https://github.com/file/file/commit/1aec04dbf8a24b8a6ba64c4f74efa0628e36db0b
References:
http://mx.gw.com/pipermail/file/2012/000914.html
http://www.openwall.com/lists/oss-security/2012/02/20/7
http://mx.gw.com/pipermail/file/2012/000914.htmlhttp://www.debian.org/security/2012/dsa-2422http://www.mandriva.com/security/advisories?name=MDVSA-2012:035http://www.ubuntu.com/usn/USN-2123-1https://github.com/glensc/file/commit/1859fdb4e67c49c463c4e0078054335cd46ba295https://github.com/glensc/file/commit/1aec04dbf8a24b8a6ba64c4f74efa0628e36db0bhttp://mx.gw.com/pipermail/file/2012/000914.htmlhttp://www.debian.org/security/2012/dsa-2422http://www.mandriva.com/security/advisories?name=MDVSA-2012:035http://www.ubuntu.com/usn/USN-2123-1https://github.com/glensc/file/commit/1859fdb4e67c49c463c4e0078054335cd46ba295https://github.com/glensc/file/commit/1aec04dbf8a24b8a6ba64c4f74efa0628e36db0b
2012-07-17
Published