MGASA-2014-0092
Dashboard / Vulnerabilities / MGASA-2014-0092
Summary: Updated file package fixes security vulnerability
Details: It was discovered that file before 5.17 contains a flaw in the handling of "indirect" magic rules in the libmagic library, which leads to an infinite recursion when trying to determine the file type of certain files (CVE-2014-1943). Additionally, other well-crafted files might result in long computation times (while using 100% CPU) and overlong results. The affected packages have been patched to correct these flaws.
References: https://advisories.mageia.org/MGASA-2014-0092.html, https://bugs.mageia.org/show_bug.cgi?id=12807, http://www.debian.org/security/2014/dsa-2861
Affected packages
Package
Name: file
Purl: pkg:rpm/mageia/file?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
