CVE-2014-8117
published 2014-12-17CVE-2014-8117: softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via…
PriorityP425medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
5.93%
92.4th percentile
softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | file | < file 1:5.21+15-1 (bookworm) | file 1:5.21+15-1 (bookworm) |
| file_project | file | <= 5.20 | — |
| file_project | file | >= 0 < 1:5.21+15-1 | 1:5.21+15-1 |
| file_project | file | >= 0 < 1:5.21+15-1 | 1:5.21+15-1 |
| file_project | file | >= 0 < 1:5.21+15-1 | 1:5.21+15-1 |
| file_project | file | >= 0 < 1:5.21+15-1 | 1:5.21+15-1 |
| file_project | file | >= 0 < 1:5.14-2ubuntu3.3 | 1:5.14-2ubuntu3.3 |
| mageia | mageia | — | — |
| php5 | php5 | >= 0 < 5.5.9+dfsg-1ubuntu4.7 | 5.5.9+dfsg-1ubuntu4.7 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2015-03-18·CVSS 5.0
CVE-2014-8117 [MEDIUM] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
Thomas Jarosch discovered that PHP incorrectly limited recursion in the
fileinfo extension. A remote attacker could possibly use this issue to
cause PHP to consume resources or crash, resulting in a denial of service.
(CVE-2014-8117)
S. Paraschoudis discovered that PHP incorrectly handled memory in the
enchant binding. A remote attacker could use this issue to cause PHP to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2014-9705)
Taoguang Chen discovered that PHP incorrectly handled unserializing
objects. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2015-0273)
It was discovered that
Ubuntu
file vulnerabilities
vendor_ubuntu·2015-02-04·CVSS 5.0
CVE-2014-3710 [MEDIUM] file vulnerabilities
Title: file vulnerabilities
Summary: file could be made to crash if it opened a specially crafted file.
Francisco Alonso discovered that file incorrectly handled certain ELF
files. An attacker could use this issue to cause file to crash, resulting
in a denial of service. (CVE-2014-3710)
Thomas Jarosch discovered that file incorrectly handled certain ELF files.
An attacker could use this issue to cause file to hang or crash, resulting
in a denial of service. (CVE-2014-8116)
Thomas Jarosch discovered that file incorrectly limited recursion. An
attacker could use this issue to cause file to hang or crash, resulting in
a denial of service. (CVE-2014-8117)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
file: denial of service issue (resource consumption)
vendor_redhat·2014-12-16·CVSS 5.0
CVE-2014-8117 [MEDIUM] CWE-400 file: denial of service issue (resource consumption)
file: denial of service issue (resource consumption)
softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors.
A flaw was found in the way the File Information (fileinfo) extension parsed Executable and Linkable Format (ELF) files. A remote attacker could use this flaw to cause a PHP application using fileinfo to consume an excessive amount of system resources.
Package: file (Red Hat Enterprise Linux 5) - Will not fix
Package: php (Red Hat Enterprise Linux 5) - Not affected
Package: php53 (Red Hat Enterprise Linux 5) - Not affected
Package: php (Red Hat Enterprise Linux 6) - Not affected
Package: php (Red Hat Enterprise Linux 7) - Not affected
Package: php54-php (
BSD
FreeBSD-SA-14:28.file: Multiple vulnerabilities in file(1) and libmagic(3)
bsd_advisories·2014-12-10·CVSS 5.0
CVE-2014-3710 [MEDIUM] FreeBSD-SA-14:28.file: Multiple vulnerabilities in file(1) and libmagic(3)
FreeBSD-SA-14:28.file Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities in file(1) and libmagic(3)
Category: contrib
Module: file
Announced: 2014-12-10
Affects: All supported versions of FreeBSD.
Credits: Thomas Jarosch of Intra2net AG
Corrected: 2014-12-10 08:26:53 UTC (stable/10, 10.1-STABLE)
2014-12-10 08:35:55 UTC (releng/10.1, 10.1-RELEASE-p1)
2014-12-10 08:36:07 UTC (releng/10.0, 10.0-RELEASE-p13)
2014-12-10 08:31:41 UTC (stable/9, 9.3-STABLE)
2014-12-10 08:36:40 UTC (releng/9.3, 9.3-RELEASE-p6)
2014-12-10 08:36:40 UTC (releng/9.2, 9.2-RELEASE-p16)
2014-12-10 08:36:40 UTC (releng/9.1, 9.1-RELEASE-p23)
2014-12-10 08:31:41 UTC (stable/8, 8.4-STABLE)
2014-12-10 08:36:40 UTC (releng/8.4, 8.4-RELEASE-p20)
CVE Name: CVE-2014-3710, CVE-2014-8116, CVE-2014-8117
For gen
Debian
CVE-2014-8117: file - softmagic.c in file before 5.21 does not properly limit recursion, which allows ...
vendor_debian·2014·CVSS 5.0
CVE-2014-8117 [MEDIUM] CVE-2014-8117: file - softmagic.c in file before 5.21 does not properly limit recursion, which allows ...
softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1:5.21+15-1)
bullseye: resolved (fixed in 1:5.21+15-1)
forky: resolved (fixed in 1:5.21+15-1)
sid: resolved (fixed in 1:5.21+15-1)
trixie: resolved (fixed in 1:5.21+15-1)
GHSA
GHSA-7cj4-vm7w-5gqx: softmagic
ghsa_unreviewed·2022-05-14
CVE-2014-8117 [MEDIUM] GHSA-7cj4-vm7w-5gqx: softmagic
softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors.
OSV
php5 vulnerabilities
osv·2015-03-18·CVSS 5.0
CVE-2014-8117 [MEDIUM] php5 vulnerabilities
php5 vulnerabilities
Thomas Jarosch discovered that PHP incorrectly limited recursion in the
fileinfo extension. A remote attacker could possibly use this issue to
cause PHP to consume resources or crash, resulting in a denial of service.
(CVE-2014-8117)
S. Paraschoudis discovered that PHP incorrectly handled memory in the
enchant binding. A remote attacker could use this issue to cause PHP to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2014-9705)
Taoguang Chen discovered that PHP incorrectly handled unserializing
objects. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2015-0273)
It was discovered that PHP incorrectly handled memory in the phar
extension. A re
OSV
file vulnerabilities
osv·2015-02-04·CVSS 5.0
CVE-2014-3710 [MEDIUM] file vulnerabilities
file vulnerabilities
Francisco Alonso discovered that file incorrectly handled certain ELF
files. An attacker could use this issue to cause file to crash, resulting
in a denial of service. (CVE-2014-3710)
Thomas Jarosch discovered that file incorrectly handled certain ELF files.
An attacker could use this issue to cause file to hang or crash, resulting
in a denial of service. (CVE-2014-8116)
Thomas Jarosch discovered that file incorrectly limited recursion. An
attacker could use this issue to cause file to hang or crash, resulting in
a denial of service. (CVE-2014-8117)
OSV
CVE-2014-8117: softmagic
osv·2014-12-17·CVSS 5.0
CVE-2014-8117 [MEDIUM] CVE-2014-8117: softmagic
softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-8117 file: denial of service issue (resource consumption)
bugzilla·2014-12-16·CVSS 5.0
CVE-2014-8117 [MEDIUM] CVE-2014-8117 file: denial of service issue (resource consumption)
CVE-2014-8117 file: denial of service issue (resource consumption)
Thomas Jarosch of Intra2net AG reported a denial of service issue (resource consumption) in the ELF parser used by file(1). Using file(1) on a specially-crafted ELF binary could lead to a denial of service (resource consumption).
Upstream fix:
https://github.com/file/file/commit/6f737ddfadb596d7d4a993f7ed2141ffd664a81c
Due to some regressions found when testing, the following commits are also required:
https://github.com/file/file/commit/8a905717660395b38ec4966493f6f1cf2f33946c
https://github.com/file/file/commit/90018fe22ff8b74a22fcd142225b0a00f3f12677
https://github.com/file/file/commit/6bf45271eb8e0e6577b92042ce2003ba998d1686
Refer also to bug 1171580 (CVE-2014-8116).
Acknowledgements:
Name: Thomas Jarosch (Intra
Bugzilla
CVE-2014-8116 CVE-2014-8117 file: various flaws [fedora-all]
bugzilla·2014-12-16·CVSS 5.0
CVE-2014-8116 [MEDIUM] CVE-2014-8116 CVE-2014-8117 file: various flaws [fedora-all]
CVE-2014-8116 CVE-2014-8117 file: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While onl
Bugzilla
CVE-2014-8116 file: multiple denial of service issues (resource consumption)
bugzilla·2014-12-08·CVSS 5.0
CVE-2014-8116 [MEDIUM] CVE-2014-8116 file: multiple denial of service issues (resource consumption)
CVE-2014-8116 file: multiple denial of service issues (resource consumption)
Thomas Jarosch of Intra2net AG reported a number of denial of service issues (resource consumption) in the ELF parser used by file(1). Using file(1) on a specially-crafted ELF binary could lead to a denial of service (resource consumption).
Upstream fixes:
https://github.com/file/file/commit/b4c01141e5367f247b84dcaf6aefbb4e741842b8
https://github.com/file/file/commit/d7cdad007c507e6c79f51f058dd77fab70ceb9f6
Due to some regressions found when testing, the following commits are also required:
https://github.com/file/file/commit/8a905717660395b38ec4966493f6f1cf2f33946c
https://github.com/file/file/commit/90018fe22ff8b74a22fcd142225b0a00f3f12677
https://github.com/file/file/commit/6bf45271eb8e0e6577b92042ce2003ba
http://advisories.mageia.org/MGASA-2015-0040.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0760.htmlhttp://seclists.org/oss-sec/2014/q4/1056http://secunia.com/advisories/61944http://secunia.com/advisories/62081http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/71692http://www.securitytracker.com/id/1031344http://www.ubuntu.com/usn/USN-2494-1http://www.ubuntu.com/usn/USN-2535-1https://github.com/file/file/blob/00cef282a902a4a6709bbbbb933ee397768caa38/ChangeLoghttps://github.com/file/file/commit/6f737ddfadb596d7d4a993f7ed2141ffd664a81chttps://www.freebsd.org/security/advisories/FreeBSD-SA-14:28.file.aschttp://advisories.mageia.org/MGASA-2015-0040.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0760.htmlhttp://seclists.org/oss-sec/2014/q4/1056http://secunia.com/advisories/61944http://secunia.com/advisories/62081http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/71692http://www.securitytracker.com/id/1031344http://www.ubuntu.com/usn/USN-2494-1http://www.ubuntu.com/usn/USN-2535-1https://github.com/file/file/blob/00cef282a902a4a6709bbbbb933ee397768caa38/ChangeLoghttps://github.com/file/file/commit/6f737ddfadb596d7d4a993f7ed2141ffd664a81chttps://www.freebsd.org/security/advisories/FreeBSD-SA-14:28.file.asc
2014-12-17
Published