CVE-2014-2270

NONE EPSS 90.0%
Published Mar 14, 201412y ago · Modified Jun 17, 20262w ago
Find Similar
Published Mar 14, 2014 12y ago
Last Modified Jun 17, 2026 2w ago

Description

softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.

Threat Intelligence

EPSS Exploit Probability
90.0% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer Memory Safety

Affected Products 13

VendorProductVersionRange
file_projectfile* <5.17
phpphp* <5.4.26
phpphp*≥5.5.0  –  <5.5.10
debiandebian_linux6.0any
debiandebian_linux7.0any
debiandebian_linux8.0any
canonicalubuntu_linux10.04any
canonicalubuntu_linux12.04any
canonicalubuntu_linux12.10any
canonicalubuntu_linux13.10any
opensuseopensuse11.4any
opensuseopensuse12.3any
opensuseopensuse13.1any

References 15

  • bugs.gw.com http://bugs.gw.com/view.php?id=313
    Broken LinkPatch
  • lists.opensuse.org http://lists.opensuse.org/opensuse-updates/2014-03/msg00034.html
    Mailing ListThird Party Advisory
  • lists.opensuse.org http://lists.opensuse.org/opensuse-updates/2014-03/msg00037.html
    Mailing ListThird Party Advisory
  • lists.opensuse.org http://lists.opensuse.org/opensuse-updates/2014-03/msg00084.html
    Mailing ListThird Party Advisory
  • rhn.redhat.com http://rhn.redhat.com/errata/RHSA-2014-1765.html
    Third Party Advisory
  • seclists.org http://seclists.org/oss-sec/2014/q1/473
    Mailing ListPatchThird Party Advisory
  • seclists.org http://seclists.org/oss-sec/2014/q1/504
    Mailing ListPatchThird Party Advisory
  • seclists.org http://seclists.org/oss-sec/2014/q1/505
    Mailing ListPatchThird Party Advisory
  • support.apple.com http://support.apple.com/kb/HT6443
    Third Party Advisory
  • debian.org http://www.debian.org/security/2014/dsa-2873
    Third Party Advisory
  • php.net http://www.php.net/ChangeLog-5.php
    Release NotesVendor Advisory
  • ubuntu.com http://www.ubuntu.com/usn/USN-2162-1
    Third Party Advisory
  • ubuntu.com http://www.ubuntu.com/usn/USN-2163-1
    Third Party Advisory
  • github.com https://github.com/file/file/commit/447558595a3650db2886cd2f416ad0beba965801
    PatchThird Party Advisory
  • security.gentoo.org https://security.gentoo.org/glsa/201503-08
    Third Party Advisory

Remediation

  • bugs.gw.com http://bugs.gw.com/view.php?id=313
    Broken LinkPatch
  • seclists.org http://seclists.org/oss-sec/2014/q1/473
    Mailing ListPatchThird Party Advisory
  • seclists.org http://seclists.org/oss-sec/2014/q1/504
    Mailing ListPatchThird Party Advisory
  • seclists.org http://seclists.org/oss-sec/2014/q1/505
    Mailing ListPatchThird Party Advisory
  • github.com https://github.com/file/file/commit/447558595a3650db2886cd2f416ad0beba965801
    PatchThird Party Advisory