CVE-2014-3538Zoulas File vulnerability

12 documents9 sources
Severity
5.0MEDIUMNVD
EPSS
21.0%
top 4.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 3
Latest updateMay 14

Description

file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7345.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages4 packages

Debianfile_project/file< 1:5.19-1+3
Ubuntufile_project/file< 1:5.14-2ubuntu3.1
NVDphp/php5.4.05.4.32+1

Also affects: Debian Linux 7.0, 8.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-p2f8-8pr7-gprp: file before 52022-05-14
OSV
file vulnerabilities2014-07-15
OSV
CVE-2014-3538: file before 52014-07-03
CVEList
CVE-2014-3538: file before 52014-07-03

📋Vendor Advisories

4
Ubuntu
file vulnerabilities2014-07-15
Red Hat
file: unrestricted regular expression matching2014-06-27
Debian
CVE-2014-3538: file - file before 5.19 does not properly restrict the amount of data read during a reg...2014
Apple
CVE-2014-3538: OS X Yosemite v10.10.3 and Security Update 2015-004

💬Community

3
Bugzilla
CVE-2015-4604 CVE-2015-4605 php: denial of service when processing a crafted file with Fileinfo2015-04-20
Bugzilla
CVE-2014-0235 php: file: extensive backtracking in awk rule regular expression (incomplete fix for CVE-2013-7345) [fedora-all]2014-06-30
Bugzilla
CVE-2014-3538 file: unrestricted regular expression matching2014-05-15
CVE-2014-3538 — Christos Zoulas File vulnerability | cvebase