cbcvebase.
CVE-2014-1943
published 2014-02-18

CVE-2014-1943: Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted…

PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
5.07%
91.4th percentile
Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted indirect offset value in the magic of a file.

Affected

14 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianfile< file 1:5.17-0.1 (bookworm)file 1:5.17-0.1 (bookworm)
file_projectfile>= 0 < 1:5.17-0.11:5.17-0.1
file_projectfile>= 0 < 1:5.17-0.11:5.17-0.1
file_projectfile>= 0 < 1:5.17-0.11:5.17-0.1
file_projectfile>= 0 < 1:5.17-0.11:5.17-0.1
fine_free_file_projectfine_free_file< 5.175.17
phpphp>= 5.4.0 < 5.4.265.4.26
phpphp>= 5.5.0 < 5.5.105.5.10

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_ubuntu6.8MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.