CVE-2014-9653
published 2015-03-30CVE-2014-9653: readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that…
PriorityP338high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.65%
90.7th percentile
readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory access) or possibly have unspecified other impact via a crafted ELF file.
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | file | < file 1:5.22+15-1 (bookworm) | file 1:5.22+15-1 (bookworm) |
| file_project | file | <= 5.21 | — |
| file_project | file | >= 0 < 1:5.22+15-1 | 1:5.22+15-1 |
| file_project | file | >= 0 < 1:5.22+15-1 | 1:5.22+15-1 |
| file_project | file | >= 0 < 1:5.22+15-1 | 1:5.22+15-1 |
| file_project | file | >= 0 < 1:5.22+15-1 | 1:5.22+15-1 |
| file_project | file | >= 0 < 1:5.14-2ubuntu3.4 | 1:5.14-2ubuntu3.4 |
| file_project | file | >= 0 < 1:5.25-2ubuntu1.1 | 1:5.25-2ubuntu1.1 |
| file_project | file | >= 0 < 1:5.32-2ubuntu0.1 | 1:5.32-2ubuntu0.1 |
| php | php | <= 5.4.36 | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-px78-rrg6-77hf: readelf
ghsa_unreviewed·2022-05-14
CVE-2014-9653 [HIGH] CWE-20 GHSA-px78-rrg6-77hf: readelf
readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory access) or possibly have unspecified other impact via a crafted ELF file.
OSV
file vulnerabilities
osv·2018-06-14·CVSS 5.0
CVE-2014-9620 [MEDIUM] file vulnerabilities
file vulnerabilities
Alexander Cherepanov discovered that file incorrectly handled a large
number of notes. An attacker could use this issue to cause a denial of
service. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-9620)
Alexander Cherepanov discovered that file incorrectly handled certain long
strings. An attacker could use this issue to cause a denial of service.
This issue only affected Ubuntu 14.04 LTS. (CVE-2014-9621)
Alexander Cherepanov discovered that file incorrectly handled certain
malformed ELF files. An attacker could use this issue to cause a denial of
service, or possibly execute arbitrary code. This issue only affected
Ubuntu 14.04 LTS. (CVE-2014-9653)
It was discovered that file incorrectly handled certain magic files. An
attacker could use this issue with a sp
OSV
CVE-2014-9653: readelf
osv·2015-03-30·CVSS 7.5
CVE-2014-9653 [HIGH] CVE-2014-9653: readelf
readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory access) or possibly have unspecified other impact via a crafted ELF file.
Ubuntu
file vulnerabilities
vendor_ubuntu·2018-06-14·CVSS 5.0
CVE-2015-8865 [MEDIUM] file vulnerabilities
Title: file vulnerabilities
Summary: Several security issues were fixed in file.
Alexander Cherepanov discovered that file incorrectly handled a large
number of notes. An attacker could use this issue to cause a denial of
service. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-9620)
Alexander Cherepanov discovered that file incorrectly handled certain long
strings. An attacker could use this issue to cause a denial of service.
This issue only affected Ubuntu 14.04 LTS. (CVE-2014-9621)
Alexander Cherepanov discovered that file incorrectly handled certain
malformed ELF files. An attacker could use this issue to cause a denial of
service, or possibly execute arbitrary code. This issue only affected
Ubuntu 14.04 LTS. (CVE-2014-9653)
It was discovered that file incorrectly handled ce
Red Hat
file: malformed elf file causes access to uninitialized memory
vendor_redhat·2014-12-16·CVSS 7.5
CVE-2014-9653 [HIGH] CWE-125 file: malformed elf file causes access to uninitialized memory
file: malformed elf file causes access to uninitialized memory
readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory access) or possibly have unspecified other impact via a crafted ELF file.
A flaw was found in the way the File Information (fileinfo) extension parsed Executable and Linkable Format (ELF) files. A remote attacker could use this flaw to cause a PHP application using fileinfo to crash or disclose certain portions of server memory.
Package: cdrtools (Red Hat Enterprise Linux 5) - Not affected
Package: file (Red Hat Enterprise Linux
Debian
CVE-2014-9653: file - readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5...
vendor_debian·2014·CVSS 7.5
CVE-2014-9653 [HIGH] CVE-2014-9653: file - readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5...
readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory access) or possibly have unspecified other impact via a crafted ELF file.
Scope: local
bookworm: resolved (fixed in 1:5.22+15-1)
bullseye: resolved (fixed in 1:5.22+15-1)
forky: resolved (fixed in 1:5.22+15-1)
sid: resolved (fixed in 1:5.22+15-1)
trixie: resolved (fixed in 1:5.22+15-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-9653 file: malformed elf file causes access to uninitialized memory
bugzilla·2015-02-06·CVSS 7.5
CVE-2014-9653 [HIGH] CVE-2014-9653 file: malformed elf file causes access to uninitialized memory
CVE-2014-9653 file: malformed elf file causes access to uninitialized memory
It was reported [1][2] that a malformed elf file can cause file urility to access invalid memory.
Upstream fixes that correct this:
https://github.com/file/file/commit/445c8fb0ebff85195be94cd9f7e1df89cade5c7f
https://github.com/file/file/commit/e96f86b5311572be1360ee0bb05d4926f8df3189
[1]: http://mx.gw.com/pipermail/file/2014/001649.html
[2]: http://bugs.gw.com/view.php?id=409
Discussion:
Created file tracking bugs for this issue:
Affects: fedora-all [bug 1190118]
---
file-5.22-2.fc21 has been pushed to the Fedora 21 stable repository. If problems still persist, please make note of it in this bug report.
---
Are there plans (or has this already been) to backport this patch to any EL releases?
---
This i
Bugzilla
CVE-2014-9653 file: malformed elf file causes access to uninitialized memory [fedora-all]
bugzilla·2015-02-06·CVSS 7.5
CVE-2014-9653 [HIGH] CVE-2014-9653 file: malformed elf file causes access to uninitialized memory [fedora-all]
CVE-2014-9653 file: malformed elf file causes access to uninitialized memory [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
http://bugs.gw.com/view.php?id=409http://marc.info/?l=bugtraq&m=143748090628601&w=2http://marc.info/?l=bugtraq&m=144050155601375&w=2http://mx.gw.com/pipermail/file/2014/001649.htmlhttp://openwall.com/lists/oss-security/2015/02/05/13http://php.net/ChangeLog-5.phphttp://rhn.redhat.com/errata/RHSA-2016-0760.htmlhttp://www.debian.org/security/2015/dsa-3196http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/72516https://github.com/file/file/commit/445c8fb0ebff85195be94cd9f7e1df89cade5c7fhttps://security.gentoo.org/glsa/201701-42https://usn.ubuntu.com/3686-1/http://bugs.gw.com/view.php?id=409http://marc.info/?l=bugtraq&m=143748090628601&w=2http://marc.info/?l=bugtraq&m=144050155601375&w=2http://mx.gw.com/pipermail/file/2014/001649.htmlhttp://openwall.com/lists/oss-security/2015/02/05/13http://php.net/ChangeLog-5.phphttp://rhn.redhat.com/errata/RHSA-2016-0760.htmlhttp://www.debian.org/security/2015/dsa-3196http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/72516https://github.com/file/file/commit/445c8fb0ebff85195be94cd9f7e1df89cade5c7fhttps://security.gentoo.org/glsa/201701-42https://usn.ubuntu.com/3686-1/
2015-03-30
Published