Vulnerability Description
softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| File Project | File | < 5.17 |
| Php | Php | < 5.4.26 |
| Debian | Debian Linux | 6.0 |
| Canonical | Ubuntu Linux | 10.04 |
| Opensuse | Opensuse | 11.4 |
Related Weaknesses (CWE)
References
- http://bugs.gw.com/view.php?id=313Broken LinkPatch
- http://lists.opensuse.org/opensuse-updates/2014-03/msg00034.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-03/msg00037.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-03/msg00084.htmlMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1765.htmlThird Party Advisory
- http://seclists.org/oss-sec/2014/q1/473Mailing ListPatchThird Party Advisory
- http://seclists.org/oss-sec/2014/q1/504Mailing ListPatchThird Party Advisory
- http://seclists.org/oss-sec/2014/q1/505Mailing ListPatchThird Party Advisory
- http://support.apple.com/kb/HT6443Third Party Advisory
- http://www.debian.org/security/2014/dsa-2873Third Party Advisory
- http://www.php.net/ChangeLog-5.phpRelease NotesVendor Advisory
- http://www.ubuntu.com/usn/USN-2162-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2163-1Third Party Advisory
- https://github.com/file/file/commit/447558595a3650db2886cd2f416ad0beba965801PatchThird Party Advisory
- https://security.gentoo.org/glsa/201503-08Third Party Advisory
FAQ
What is CVE-2014-2270?
CVE-2014-2270 is a vulnerability with a CVSS score of 4.3 (MEDIUM). softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE execut...
How severe is CVE-2014-2270?
CVE-2014-2270 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-2270?
Check the references section above for vendor advisories and patch information. Affected products include: File Project File, Php Php, Debian Debian Linux, Canonical Ubuntu Linux, Opensuse Opensuse.