CVE-2013-7345Inefficient Algorithmic Complexity in Zoulas File

Severity
5.0MEDIUMNVD
EPSS
3.2%
top 13.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 24
Latest updateMay 17

Description

The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses multiple wildcards with unlimited repetitions, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted ASCII file that triggers a large amount of backtracking, as demonstrated via a file with many newline characters.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages4 packages

Debianfile_project/file< 1:5.17-0.1+3
Ubuntufile_project/file< 1:5.14-2ubuntu3.1
NVDphp/php5.4.05.4.27+1

Also affects: Debian Linux 6.0, 7.0, 8.0

Patches

🔴Vulnerability Details

6
GHSA
GHSA-63f8-4qqh-pqqj: The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 52022-05-17
GHSA
GHSA-p2f8-8pr7-gprp: file before 52022-05-14
OSV
file vulnerabilities2014-07-15
CVEList
CVE-2014-3538: file before 52014-07-03
OSV
CVE-2013-7345: The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 52014-03-24

📋Vendor Advisories

5
Ubuntu
file vulnerabilities2014-07-15
Red Hat
file: unrestricted regular expression matching2014-06-27
BSD
FreeBSD-SA-14:16.file: Multiple vulnerabilities in file(1) and libmagic(3)2014-06-24
Debian
CVE-2013-7345: file - The BEGIN regular expression in the awk script detector in magic/Magdir/commands...2013
Red Hat
file: extensive backtracking in awk rule regular expression2011-12-31

💬Community

6
Bugzilla
CVE-2014-0235 file: extensive backtracking in awk rule regular expression (incomplete fix for CVE-2013-7345) [fedora-all]2014-06-30
Bugzilla
CVE-2014-0235 php: file: extensive backtracking in awk rule regular expression (incomplete fix for CVE-2013-7345) [fedora-all]2014-06-30
Bugzilla
CVE-2014-3538 file: unrestricted regular expression matching2014-05-15
Bugzilla
CVE-2013-7345 file: extensive backtracking in awk rule regular expression2014-03-24
Bugzilla
CVE-2013-7345 file: denial of service (CPU consumption) when processing certain files [fedora-all]2014-03-24
CVE-2013-7345 — Inefficient Algorithmic Complexity | cvebase