CVE-2014-3538
published 2014-07-03CVE-2014-3538: file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU…
PriorityP429medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
11.81%
95.6th percentile
file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7345.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | os_x_yosemite_v10.10.3_and_security_update_2015-004 | — | — |
| christos_zoulas | file | <= 5.18 | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| christos_zoulas | file | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | file | < file 1:5.19-1 (bookworm) | file 1:5.19-1 (bookworm) |
| file_project | file | >= 0 < 1:5.19-1 | 1:5.19-1 |
| file_project | file | >= 0 < 1:5.19-1 | 1:5.19-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
file vulnerabilities
vendor_ubuntu·2014-07-15·CVSS 5.0
CVE-2013-7345 [MEDIUM] file vulnerabilities
Title: file vulnerabilities
Summary: File could be made to crash or hang if it processed specially crafted data.
Mike Frysinger discovered that the file awk script detector used multiple
wildcard with unlimited repetitions. An attacker could use this issue to
cause file to consume resources, resulting in a denial of service.
(CVE-2013-7345)
Francisco Alonso discovered that file incorrectly handled certain CDF
documents. A attacker could use this issue to cause file to hang or crash,
resulting in a denial of service. (CVE-2014-0207, CVE-2014-3478,
CVE-2014-3479, CVE-2014-3480, CVE-2014-3487)
Jan Kaluža discovered that file did not properly restrict the amount of
data read during regex searches. An attacker could use this issue to
cause file to consume resources, resulting in a denial of
Red Hat
file: unrestricted regular expression matching
vendor_redhat·2014-06-27·CVSS 5.0
CVE-2014-3538 [MEDIUM] file: unrestricted regular expression matching
file: unrestricted regular expression matching
file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7345.
Multiple flaws were found in the File Information (fileinfo) extension regular expression rules for detecting various files. A remote attacker could use either of these flaws to cause a PHP application using fileinfo to consume an excessive amount of CPU.
Package: cdrtools (Red Hat Enterprise Linux 5) - Not affected
Package: file (Red Hat Enterprise Linux 5) - Not affected
Package: php (Red Hat Enterprise Linux 5) -
Debian
CVE-2014-3538: file - file before 5.19 does not properly restrict the amount of data read during a reg...
vendor_debian·2014·CVSS 5.0
CVE-2014-3538 [MEDIUM] CVE-2014-3538: file - file before 5.19 does not properly restrict the amount of data read during a reg...
file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7345.
Scope: local
bookworm: resolved (fixed in 1:5.19-1)
bullseye: resolved (fixed in 1:5.19-1)
forky: resolved (fixed in 1:5.19-1)
sid: resolved (fixed in 1:5.19-1)
trixie: resolved (fixed in 1:5.19-1)
Apple
CVE-2014-3538: OS X Yosemite v10.10.3 and Security Update 2015-004
vendor_apple·CVSS 5.0
CVE-2014-3538 [MEDIUM] CVE-2014-3538: OS X Yosemite v10.10.3 and Security Update 2015-004
Apple Security Update: About the security content of OS X Yosemite v10.10.3 and Security Update 2015-004
Product: OS X Yosemite v10.10.3 and Security Update 2015-004
CVE: CVE-2014-3538
Component: CVE-2014-3538
GHSA
GHSA-p2f8-8pr7-gprp: file before 5
ghsa_unreviewed·2022-05-14·CVSS 5.0
CVE-2014-3538 [MEDIUM] GHSA-p2f8-8pr7-gprp: file before 5
file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7345.
OSV
file vulnerabilities
osv·2014-07-15·CVSS 5.0
CVE-2013-7345 [MEDIUM] file vulnerabilities
file vulnerabilities
Mike Frysinger discovered that the file awk script detector used multiple
wildcard with unlimited repetitions. An attacker could use this issue to
cause file to consume resources, resulting in a denial of service.
(CVE-2013-7345)
Francisco Alonso discovered that file incorrectly handled certain CDF
documents. A attacker could use this issue to cause file to hang or crash,
resulting in a denial of service. (CVE-2014-0207, CVE-2014-3478,
CVE-2014-3479, CVE-2014-3480, CVE-2014-3487)
Jan Kaluža discovered that file did not properly restrict the amount of
data read during regex searches. An attacker could use this issue to
cause file to consume resources, resulting in a denial of service.
(CVE-2014-3538)
OSV
CVE-2014-3538: file before 5
osv·2014-07-03·CVSS 5.0
CVE-2014-3538 [MEDIUM] CVE-2014-3538: file before 5
file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7345.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-4604 CVE-2015-4605 php: denial of service when processing a crafted file with Fileinfo
bugzilla·2015-04-20·CVSS 5.0
CVE-2015-4604 [MEDIUM] CVE-2015-4604 CVE-2015-4605 php: denial of service when processing a crafted file with Fileinfo
CVE-2015-4604 CVE-2015-4605 php: denial of service when processing a crafted file with Fileinfo
PHP versions 5.4.40, 5.5.24, and 5.6.8 provide a fix for PHP Fileinfo extension which could crash PHP process when processing a crafted file, causing a denial of service.
Upstream fix:
http://git.php.net/?p=php-src.git;a=commitdiff;h=f938112c495b0d26572435c0be73ac0bfe642ecd
Upstream bug:
https://bugs.php.net/bug.php?id=68819
Discussion:
Created file tracking bugs for this issue:
Affects: fedora-all [bug 1213451]
---
Created php tracking bugs for this issue:
Affects: fedora-all [bug 1213456]
---
php-5.6.8-1.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
---
php-5.6.8-1.fc21 has been pushed to the Fedora 2
Bugzilla
CVE-2014-0235 php: file: extensive backtracking in awk rule regular expression (incomplete fix for CVE-2013-7345) [fedora-all]
bugzilla·2014-06-30·CVSS 5.0
CVE-2014-0235 [MEDIUM] CVE-2014-0235 php: file: extensive backtracking in awk rule regular expression (incomplete fix for CVE-2013-7345) [fedora-all]
CVE-2014-0235 php: file: extensive backtracking in awk rule regular expression (incomplete fix for CVE-2013-7345) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field wh
Bugzilla
CVE-2014-3538 file: unrestricted regular expression matching
bugzilla·2014-05-15·CVSS 5.0
CVE-2014-3538 [MEDIUM] CVE-2014-3538 file: unrestricted regular expression matching
CVE-2014-3538 file: unrestricted regular expression matching
It was discovered the original upstream fix for the CVE-2013-7345 issue (bug 1079846) did not sufficiently address the problem. A specially-crafted input file could still cause file to use an excessive amount of CPU time when trying to detect file type using awk regular expression rule.
Discussion:
Patch proposed from Jan Kaluza:
0 search/16384 BEGIN
>0 regex =^\\s{0,100}BEGIN\\s{0,100}[{] awk script text
Not fixed upstream yet.
---
Acknowledgment:
Name: Jan Kaluža (Red Hat Web Stack Team)
---
(In reply to Francisco Alonso from comment #1)
> Patch proposed from Jan Kaluza:
>
>
> 0 search/16384 BEGIN
> >0 regex =^\\s{0,100}BEGIN\\s{0,100}[{] awk script text
This fix is also insufficient and easy to bypass. The first r
http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlhttp://mx.gw.com/pipermail/file/2014/001553.htmlhttp://openwall.com/lists/oss-security/2014/06/30/7http://rhn.redhat.com/errata/RHSA-2014-1327.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1765.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1766.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0760.htmlhttp://secunia.com/advisories/60696http://www.debian.org/security/2014/dsa-3008http://www.debian.org/security/2014/dsa-3021http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/68348https://bugzilla.redhat.com/show_bug.cgi?id=1098222https://github.com/file/file/commit/4a284c89d6ef11aca34da65da7d673050a5ea320https://github.com/file/file/commit/69a5a43b3b71f53b0577f41264a073f495799610https://github.com/file/file/commit/71a8b6c0d758acb0f73e2e51421a711b5e9d6668https://github.com/file/file/commit/74cafd7de9ec99a14f4480927580e501c8f852c3https://github.com/file/file/commit/758e066df72fb1ac08d2eea91ddc3973d259e991https://support.apple.com/HT204659http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlhttp://mx.gw.com/pipermail/file/2014/001553.htmlhttp://openwall.com/lists/oss-security/2014/06/30/7http://rhn.redhat.com/errata/RHSA-2014-1327.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1765.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1766.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0760.htmlhttp://secunia.com/advisories/60696http://www.debian.org/security/2014/dsa-3008http://www.debian.org/security/2014/dsa-3021http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/68348https://bugzilla.redhat.com/show_bug.cgi?id=1098222https://github.com/file/file/commit/4a284c89d6ef11aca34da65da7d673050a5ea320https://github.com/file/file/commit/69a5a43b3b71f53b0577f41264a073f495799610https://github.com/file/file/commit/71a8b6c0d758acb0f73e2e51421a711b5e9d6668https://github.com/file/file/commit/74cafd7de9ec99a14f4480927580e501c8f852c3https://github.com/file/file/commit/758e066df72fb1ac08d2eea91ddc3973d259e991https://support.apple.com/HT204659
2014-07-03
Published