CVE-2014-2270
NONE EPSS 90.0%
Published Mar 14, 201412y ago · Modified Jun 17, 20262w ago
Published Mar 14, 2014 12y ago
Last Modified Jun 17, 2026 2w ago
Description
softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.
Threat Intelligence
EPSS Exploit Probability
90.0% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 1
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer Memory Safety
Affected Products 13
| Vendor | Product | Version | Range |
|---|---|---|---|
| file_project | file | * | <5.17 |
| php | php | * | <5.4.26 |
| php | php | * | ≥5.5.0 – <5.5.10 |
| debian | debian_linux | 6.0 | any |
| debian | debian_linux | 7.0 | any |
| debian | debian_linux | 8.0 | any |
| canonical | ubuntu_linux | 10.04 | any |
| canonical | ubuntu_linux | 12.04 | any |
| canonical | ubuntu_linux | 12.10 | any |
| canonical | ubuntu_linux | 13.10 | any |
| opensuse | opensuse | 11.4 | any |
| opensuse | opensuse | 12.3 | any |
| opensuse | opensuse | 13.1 | any |
References 15
- bugs.gw.com http://bugs.gw.com/view.php?id=313
- lists.opensuse.org http://lists.opensuse.org/opensuse-updates/2014-03/msg00034.html
- lists.opensuse.org http://lists.opensuse.org/opensuse-updates/2014-03/msg00037.html
- lists.opensuse.org http://lists.opensuse.org/opensuse-updates/2014-03/msg00084.html
- rhn.redhat.com http://rhn.redhat.com/errata/RHSA-2014-1765.html
- seclists.org http://seclists.org/oss-sec/2014/q1/473
- seclists.org http://seclists.org/oss-sec/2014/q1/504
- seclists.org http://seclists.org/oss-sec/2014/q1/505
- support.apple.com http://support.apple.com/kb/HT6443
- debian.org http://www.debian.org/security/2014/dsa-2873
- php.net http://www.php.net/ChangeLog-5.php
- ubuntu.com http://www.ubuntu.com/usn/USN-2162-1
- ubuntu.com http://www.ubuntu.com/usn/USN-2163-1
- github.com https://github.com/file/file/commit/447558595a3650db2886cd2f416ad0beba965801
- security.gentoo.org https://security.gentoo.org/glsa/201503-08
Remediation
- bugs.gw.com http://bugs.gw.com/view.php?id=313
- seclists.org http://seclists.org/oss-sec/2014/q1/473
- seclists.org http://seclists.org/oss-sec/2014/q1/504
- seclists.org http://seclists.org/oss-sec/2014/q1/505
- github.com https://github.com/file/file/commit/447558595a3650db2886cd2f416ad0beba965801