MGASA-2014-0252
Dashboard / Vulnerabilities / MGASA-2014-0252
Summary: Updated file packages fix CVE-2014-0237-8
Details: Updated file packages fix security vulnerabilities: A flaw was found in the way file's Composite Document Files (CDF) format parser handle CDF files with many summary info entries. The cdf_unpack_summary_info() function unnecessarily repeatedly read the info from the same offset. This led to many file_printf() calls in cdf_file_property_info(), which caused file to use an excessive amount of CPU time when parsing a specially-crafted CDF file (CVE-2014-0237). A flaw was found in the way file parsed property information from Composite Document Files (CDF) files. A property entry with 0 elements triggers an infinite loop (CVE-2014-0238).
References: https://advisories.mageia.org/MGASA-2014-0252.html, https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-0237, https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-0238, https://bugs.mageia.org/show_bug.cgi?id=13460
Affected packages
Package
Name: file
Purl: pkg:rpm/mageia/file?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
