CVE-2014-2270
published 2014-03-14CVE-2014-2270: softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
4.32%
90.1th percentile
softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | file | < file 1:5.17-1 (bookworm) | file 1:5.17-1 (bookworm) |
| file_project | file | < 5.17 | 5.17 |
| file_project | file | >= 0 < 1:5.17-1 | 1:5.17-1 |
| file_project | file | >= 0 < 1:5.17-1 | 1:5.17-1 |
| file_project | file | >= 0 < 1:5.17-1 | 1:5.17-1 |
| file_project | file | >= 0 < 1:5.17-1 | 1:5.17-1 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| php | php | < 5.4.26 | 5.4.26 |
| php | php | >= 5.5.0 < 5.5.10 | 5.5.10 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
BSD
FreeBSD-SA-14:16.file: Multiple vulnerabilities in file(1) and libmagic(3)
bsd_advisories·2014-06-24·CVSS 6.5
CVE-2012-1571 [MEDIUM] FreeBSD-SA-14:16.file: Multiple vulnerabilities in file(1) and libmagic(3)
FreeBSD-SA-14:16.file Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities in file(1) and libmagic(3)
Category: contrib
Module: file
Announced: 2014-06-24
Affects: All supported versions of FreeBSD.
Corrected: 2014-06-24 19:04:55 UTC (stable/10, 10.0-STABLE)
2014-06-24 19:05:08 UTC (releng/10.0, 10.0-RELEASE-p6)
2014-06-24 19:04:55 UTC (stable/9, 9.3-PRERELEASE)
2014-06-24 19:05:19 UTC (releng/9.3, 9.3-RC2)
2014-06-24 19:05:36 UTC (releng/9.2, 9.2-RELEASE-p9)
2014-06-24 19:05:36 UTC (releng/9.1, 9.1-RELEASE-p16)
2014-06-24 19:04:55 UTC (stable/8, 8.4-STABLE)
2014-06-24 19:05:47 UTC (releng/8.4, 8.4-RELEASE-p13)
CVE Name: CVE-2012-1571, CVE-2013-7345, CVE-2014-1943, CVE-2014-2270
For general information regarding FreeBSD Security Advisories,
including descriptions of the
Ubuntu
file vulnerability
vendor_ubuntu·2014-04-07
CVE-2014-2270 file vulnerability
Title: file vulnerability
Summary: File could be made to crash if it processed a specially crafted file.
It was discovered that file incorrectly handled PE executable files. An
attacker could use this issue to cause file to crash, resulting in a denial
of service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
PHP vulnerability
vendor_ubuntu·2014-04-07
CVE-2014-2270 PHP vulnerability
Title: PHP vulnerability
Summary: PHP could be made to crash if it processed a specially crafted file.
It was discovered that PHP's embedded libmagic library incorrectly handled
PE executables. An attacker could use this issue to cause PHP to crash,
resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2014-2270: file - softmagic.c in file before 5.17 and libmagic allows context-dependent attackers ...
vendor_debian·2014·CVSS 4.3
CVE-2014-2270 [MEDIUM] CVE-2014-2270: file - softmagic.c in file before 5.17 and libmagic allows context-dependent attackers ...
softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.
Scope: local
bookworm: resolved (fixed in 1:5.17-1)
bullseye: resolved (fixed in 1:5.17-1)
forky: resolved (fixed in 1:5.17-1)
sid: resolved (fixed in 1:5.17-1)
trixie: resolved (fixed in 1:5.17-1)
Red Hat
file: out-of-bounds access in search rules with offsets from input file
vendor_redhat·2013-12-20·CVSS 4.3
CVE-2014-2270 [MEDIUM] CWE-190 file: out-of-bounds access in search rules with offsets from input file
file: out-of-bounds access in search rules with offsets from input file
softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.
A denial of service flaw was found in the way the File Information (fileinfo) extension handled search rules. A remote attacker could use this flaw to cause a PHP application using fileinfo to crash or consume an excessive amount of CPU.
Statement: This issue did not affect the php packages as shipped with Red Hat Enterprise Linux 5. This issue did not affect the php packages as shipped with Red Hat Enterprise Linux 7.
Package: cdrtools (Red Hat Enterprise Linux 5) - Will not fix
Package: file (Red Hat Enterpris
GHSA
GHSA-33vf-9722-2226: softmagic
ghsa_unreviewed·2022-05-17
CVE-2014-2270 [MEDIUM] CWE-119 GHSA-33vf-9722-2226: softmagic
softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.
OSV
CVE-2014-2270: softmagic
osv·2014-03-14·CVSS 4.3
CVE-2014-2270 [MEDIUM] CVE-2014-2270: softmagic
softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-2270 file: out-of-bounds memory access when parsing Portable Executable (PE) format files [fedora-all]
bugzilla·2014-03-06·CVSS 4.3
CVE-2014-2270 [MEDIUM] CVE-2014-2270 file: out-of-bounds memory access when parsing Portable Executable (PE) format files [fedora-all]
CVE-2014-2270 file: out-of-bounds memory access when parsing Portable Executable (PE) format files [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when avail
Bugzilla
CVE-2014-2270 php: file: out-of-bounds memory access when parsing Portable Executable (PE) format files [fedora-all]
bugzilla·2014-03-06·CVSS 4.3
CVE-2014-2270 [MEDIUM] CVE-2014-2270 php: file: out-of-bounds memory access when parsing Portable Executable (PE) format files [fedora-all]
CVE-2014-2270 php: file: out-of-bounds memory access when parsing Portable Executable (PE) format files [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when
Bugzilla
CVE-2014-2270 file: out-of-bounds access in search rules with offsets from input file
bugzilla·2014-03-04·CVSS 4.3
CVE-2014-2270 [MEDIUM] CVE-2014-2270 file: out-of-bounds access in search rules with offsets from input file
CVE-2014-2270 file: out-of-bounds access in search rules with offsets from input file
A flaw was found in the way the file utility determined the type of Portable Executable (PE) format files, the executable format used on Windows. A malicious PE file could cause the file utility to crash or, potentially, execute arbitrary code.
Upstream report: http://bugs.gw.com/view.php?id=313
Upstream fix: https://github.com/glensc/file/commit/447558595a3650db2886cd2f416ad0beba965801
Discussion:
CVE request: http://seclists.org/oss-sec/2014/q1/473
---
Note that the arbitrary code execution impact is a guess. The issue is still being investigated.
---
Notice, this upstream patch doesn't seems correct.
+#define OFFSET_OOB(n, o, i) ((n) = ((n) - (o)))
At least, it breaks php test suite for this
http://bugs.gw.com/view.php?id=313http://lists.opensuse.org/opensuse-updates/2014-03/msg00034.htmlhttp://lists.opensuse.org/opensuse-updates/2014-03/msg00037.htmlhttp://lists.opensuse.org/opensuse-updates/2014-03/msg00084.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1765.htmlhttp://seclists.org/oss-sec/2014/q1/473http://seclists.org/oss-sec/2014/q1/504http://seclists.org/oss-sec/2014/q1/505http://support.apple.com/kb/HT6443http://www.debian.org/security/2014/dsa-2873http://www.php.net/ChangeLog-5.phphttp://www.ubuntu.com/usn/USN-2162-1http://www.ubuntu.com/usn/USN-2163-1https://github.com/file/file/commit/447558595a3650db2886cd2f416ad0beba965801https://security.gentoo.org/glsa/201503-08http://bugs.gw.com/view.php?id=313http://lists.opensuse.org/opensuse-updates/2014-03/msg00034.htmlhttp://lists.opensuse.org/opensuse-updates/2014-03/msg00037.htmlhttp://lists.opensuse.org/opensuse-updates/2014-03/msg00084.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1765.htmlhttp://seclists.org/oss-sec/2014/q1/473http://seclists.org/oss-sec/2014/q1/504http://seclists.org/oss-sec/2014/q1/505http://support.apple.com/kb/HT6443http://www.debian.org/security/2014/dsa-2873http://www.php.net/ChangeLog-5.phphttp://www.ubuntu.com/usn/USN-2162-1http://www.ubuntu.com/usn/USN-2163-1https://github.com/file/file/commit/447558595a3650db2886cd2f416ad0beba965801https://security.gentoo.org/glsa/201503-08
2014-03-14
Published