CVE-2014-9621
published 2015-01-21CVE-2014-9621: The ELF parser in file 5.16 through 5.21 allows remote attackers to cause a denial of service via a long string.
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.98%
85.7th percentile
The ELF parser in file 5.16 through 5.21 allows remote attackers to cause a denial of service via a long string.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | file | < file 1:5.21+15-1 (bookworm) | file 1:5.21+15-1 (bookworm) |
| file_project | file | — | — |
| file_project | file | — | — |
| file_project | file | — | — |
| file_project | file | — | — |
| file_project | file | — | — |
| file_project | file | — | — |
| file_project | file | >= 0 < 1:5.21+15-1 | 1:5.21+15-1 |
| file_project | file | >= 0 < 1:5.21+15-1 | 1:5.21+15-1 |
| file_project | file | >= 0 < 1:5.21+15-1 | 1:5.21+15-1 |
| file_project | file | >= 0 < 1:5.21+15-1 | 1:5.21+15-1 |
| file_project | file | >= 0 < 1:5.14-2ubuntu3.4 | 1:5.14-2ubuntu3.4 |
| file_project | file | >= 0 < 1:5.25-2ubuntu1.1 | 1:5.25-2ubuntu1.1 |
| file_project | file | >= 0 < 1:5.32-2ubuntu0.1 | 1:5.32-2ubuntu0.1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-37mq-9v9g-wmfw: The ELF parser in file 5
ghsa_unreviewed·2022-05-14
CVE-2014-9621 [MEDIUM] GHSA-37mq-9v9g-wmfw: The ELF parser in file 5
The ELF parser in file 5.16 through 5.21 allows remote attackers to cause a denial of service via a long string.
OSV
file vulnerabilities
osv·2018-06-14·CVSS 5.0
CVE-2014-9620 [MEDIUM] file vulnerabilities
file vulnerabilities
Alexander Cherepanov discovered that file incorrectly handled a large
number of notes. An attacker could use this issue to cause a denial of
service. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-9620)
Alexander Cherepanov discovered that file incorrectly handled certain long
strings. An attacker could use this issue to cause a denial of service.
This issue only affected Ubuntu 14.04 LTS. (CVE-2014-9621)
Alexander Cherepanov discovered that file incorrectly handled certain
malformed ELF files. An attacker could use this issue to cause a denial of
service, or possibly execute arbitrary code. This issue only affected
Ubuntu 14.04 LTS. (CVE-2014-9653)
It was discovered that file incorrectly handled certain magic files. An
attacker could use this issue with a sp
OSV
CVE-2014-9621: The ELF parser in file 5
osv·2015-01-21·CVSS 5.0
CVE-2014-9621 [MEDIUM] CVE-2014-9621: The ELF parser in file 5
The ELF parser in file 5.16 through 5.21 allows remote attackers to cause a denial of service via a long string.
Ubuntu
file vulnerabilities
vendor_ubuntu·2018-06-14·CVSS 5.0
CVE-2015-8865 [MEDIUM] file vulnerabilities
Title: file vulnerabilities
Summary: Several security issues were fixed in file.
Alexander Cherepanov discovered that file incorrectly handled a large
number of notes. An attacker could use this issue to cause a denial of
service. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-9620)
Alexander Cherepanov discovered that file incorrectly handled certain long
strings. An attacker could use this issue to cause a denial of service.
This issue only affected Ubuntu 14.04 LTS. (CVE-2014-9621)
Alexander Cherepanov discovered that file incorrectly handled certain
malformed ELF files. An attacker could use this issue to cause a denial of
service, or possibly execute arbitrary code. This issue only affected
Ubuntu 14.04 LTS. (CVE-2014-9653)
It was discovered that file incorrectly handled ce
Red Hat
file: limit string printing to 100 chars
vendor_redhat·2015-01-03·CVSS 5.0
CVE-2014-9621 [MEDIUM] CWE-770 file: limit string printing to 100 chars
file: limit string printing to 100 chars
The ELF parser in file 5.16 through 5.21 allows remote attackers to cause a denial of service via a long string.
Package: cdrtools (Red Hat Enterprise Linux 5) - Not affected
Package: file (Red Hat Enterprise Linux 5) - Not affected
Package: php53 (Red Hat Enterprise Linux 5) - Not affected
Package: rpm (Red Hat Enterprise Linux 5) - Not affected
Package: file (Red Hat Enterprise Linux 6) - Not affected
Package: php (Red Hat Enterprise Linux 6) - Not affected
Package: file (Red Hat Enterprise Linux 7) - Not affected
Package: php (Red Hat Enterprise Linux 7) - Not affected
Package: php54-php (Red Hat Software Collections) - Not affected
Package: php55-php (Red Hat Software Collections) - Not affected
Package: rh-php56-php (Red Hat Softwar
Debian
CVE-2014-9621: file - The ELF parser in file 5.16 through 5.21 allows remote attackers to cause a deni...
vendor_debian·2014·CVSS 5.0
CVE-2014-9621 [MEDIUM] CVE-2014-9621: file - The ELF parser in file 5.16 through 5.21 allows remote attackers to cause a deni...
The ELF parser in file 5.16 through 5.21 allows remote attackers to cause a denial of service via a long string.
Scope: local
bookworm: resolved (fixed in 1:5.21+15-1)
bullseye: resolved (fixed in 1:5.21+15-1)
forky: resolved (fixed in 1:5.21+15-1)
sid: resolved (fixed in 1:5.21+15-1)
trixie: resolved (fixed in 1:5.21+15-1)
No detection rules found.
No public exploits indexed.
http://advisories.mageia.org/MGASA-2015-0040.htmlhttp://mx.gw.com/pipermail/file/2014/001654.htmlhttp://mx.gw.com/pipermail/file/2015/001660.htmlhttp://www.openwall.com/lists/oss-security/2015/01/17/9https://github.com/file/file/commit/65437cee25199dbd385fb35901bc0011e164276chttps://security.gentoo.org/glsa/201503-08https://usn.ubuntu.com/3686-1/http://advisories.mageia.org/MGASA-2015-0040.htmlhttp://mx.gw.com/pipermail/file/2014/001654.htmlhttp://mx.gw.com/pipermail/file/2015/001660.htmlhttp://www.openwall.com/lists/oss-security/2015/01/17/9https://github.com/file/file/commit/65437cee25199dbd385fb35901bc0011e164276chttps://security.gentoo.org/glsa/201503-08https://usn.ubuntu.com/3686-1/
2015-01-21
Published