CVE-2014-9620
published 2015-01-21CVE-2014-9620: The ELF parser in file 5.08 through 5.21 allows remote attackers to cause a denial of service via a large number of notes.
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
4.68%
90.8th percentile
The ELF parser in file 5.08 through 5.21 allows remote attackers to cause a denial of service via a large number of notes.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | file | < file 1:5.21+15-1 (bookworm) | file 1:5.21+15-1 (bookworm) |
| file_project | file | — | — |
| file_project | file | — | — |
| file_project | file | — | — |
| file_project | file | — | — |
| file_project | file | — | — |
| file_project | file | — | — |
| file_project | file | — | — |
| file_project | file | — | — |
| file_project | file | — | — |
| file_project | file | — | — |
| file_project | file | — | — |
| file_project | file | — | — |
| file_project | file | — | — |
| file_project | file | — | — |
| file_project | file | >= 0 < 1:5.21+15-1 | 1:5.21+15-1 |
| file_project | file | >= 0 < 1:5.21+15-1 | 1:5.21+15-1 |
| file_project | file | >= 0 < 1:5.21+15-1 | 1:5.21+15-1 |
| file_project | file | >= 0 < 1:5.21+15-1 | 1:5.21+15-1 |
| file_project | file | >= 0 < 1:5.14-2ubuntu3.4 | 1:5.14-2ubuntu3.4 |
| file_project | file | >= 0 < 1:5.25-2ubuntu1.1 | 1:5.25-2ubuntu1.1 |
| file_project | file | >= 0 < 1:5.32-2ubuntu0.1 | 1:5.32-2ubuntu0.1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
file vulnerabilities
vendor_ubuntu·2018-06-14·CVSS 5.0
CVE-2015-8865 [MEDIUM] file vulnerabilities
Title: file vulnerabilities
Summary: Several security issues were fixed in file.
Alexander Cherepanov discovered that file incorrectly handled a large
number of notes. An attacker could use this issue to cause a denial of
service. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-9620)
Alexander Cherepanov discovered that file incorrectly handled certain long
strings. An attacker could use this issue to cause a denial of service.
This issue only affected Ubuntu 14.04 LTS. (CVE-2014-9621)
Alexander Cherepanov discovered that file incorrectly handled certain
malformed ELF files. An attacker could use this issue to cause a denial of
service, or possibly execute arbitrary code. This issue only affected
Ubuntu 14.04 LTS. (CVE-2014-9653)
It was discovered that file incorrectly handled ce
Red Hat
file: limit the number of ELF notes processed
vendor_redhat·2015-01-03·CVSS 5.0
CVE-2014-9620 [MEDIUM] CWE-770 file: limit the number of ELF notes processed
file: limit the number of ELF notes processed
The ELF parser in file 5.08 through 5.21 allows remote attackers to cause a denial of service via a large number of notes.
A flaw was found in the way the File Information (fileinfo) extension parsed Executable and Linkable Format (ELF) files. A remote attacker could use this flaw to crash a PHP application using fileinfo via a specially crafted ELF file.
Package: cdrtools (Red Hat Enterprise Linux 5) - Not affected
Package: file (Red Hat Enterprise Linux 5) - Will not fix
Package: php53 (Red Hat Enterprise Linux 5) - Not affected
Package: rpm (Red Hat Enterprise Linux 5) - Will not fix
Package: php (Red Hat Enterprise Linux 6) - Not affected
Package: file (Red Hat Enterprise Linux 7) - Will not fix
Package: php (Red Hat Enterprise Lin
Debian
CVE-2014-9620: file - The ELF parser in file 5.08 through 5.21 allows remote attackers to cause a deni...
vendor_debian·2014·CVSS 5.0
CVE-2014-9620 [MEDIUM] CVE-2014-9620: file - The ELF parser in file 5.08 through 5.21 allows remote attackers to cause a deni...
The ELF parser in file 5.08 through 5.21 allows remote attackers to cause a denial of service via a large number of notes.
Scope: local
bookworm: resolved (fixed in 1:5.21+15-1)
bullseye: resolved (fixed in 1:5.21+15-1)
forky: resolved (fixed in 1:5.21+15-1)
sid: resolved (fixed in 1:5.21+15-1)
trixie: resolved (fixed in 1:5.21+15-1)
GHSA
GHSA-7ffm-2w4x-4wm5: The ELF parser in file 5
ghsa_unreviewed·2022-05-14
CVE-2014-9620 [MEDIUM] GHSA-7ffm-2w4x-4wm5: The ELF parser in file 5
The ELF parser in file 5.08 through 5.21 allows remote attackers to cause a denial of service via a large number of notes.
OSV
file vulnerabilities
osv·2018-06-14·CVSS 5.0
CVE-2014-9620 [MEDIUM] file vulnerabilities
file vulnerabilities
Alexander Cherepanov discovered that file incorrectly handled a large
number of notes. An attacker could use this issue to cause a denial of
service. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-9620)
Alexander Cherepanov discovered that file incorrectly handled certain long
strings. An attacker could use this issue to cause a denial of service.
This issue only affected Ubuntu 14.04 LTS. (CVE-2014-9621)
Alexander Cherepanov discovered that file incorrectly handled certain
malformed ELF files. An attacker could use this issue to cause a denial of
service, or possibly execute arbitrary code. This issue only affected
Ubuntu 14.04 LTS. (CVE-2014-9653)
It was discovered that file incorrectly handled certain magic files. An
attacker could use this issue with a sp
OSV
CVE-2014-9620: The ELF parser in file 5
osv·2015-01-21·CVSS 5.0
CVE-2014-9620 [MEDIUM] CVE-2014-9620: The ELF parser in file 5
The ELF parser in file 5.08 through 5.21 allows remote attackers to cause a denial of service via a large number of notes.
No detection rules found.
No public exploits indexed.
http://advisories.mageia.org/MGASA-2015-0040.htmlhttp://mx.gw.com/pipermail/file/2014/001653.htmlhttp://mx.gw.com/pipermail/file/2015/001660.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0760.htmlhttp://www.debian.org/security/2015/dsa-3121http://www.openwall.com/lists/oss-security/2015/01/17/9http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securityfocus.com/bid/71715https://github.com/file/file/commit/ce90e05774dd77d86cfc8dfa6da57b32816841c4https://security.gentoo.org/glsa/201503-08https://usn.ubuntu.com/3686-1/http://advisories.mageia.org/MGASA-2015-0040.htmlhttp://mx.gw.com/pipermail/file/2014/001653.htmlhttp://mx.gw.com/pipermail/file/2015/001660.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0760.htmlhttp://www.debian.org/security/2015/dsa-3121http://www.openwall.com/lists/oss-security/2015/01/17/9http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securityfocus.com/bid/71715https://github.com/file/file/commit/ce90e05774dd77d86cfc8dfa6da57b32816841c4https://security.gentoo.org/glsa/201503-08https://usn.ubuntu.com/3686-1/
2015-01-21
Published