UBUNTU-CVE-2015-8865
Dashboard / Vulnerabilities / UBUNTU-CVE-2015-8865
UBUNTU-CVE-2015-8865
Summary:
Details: The file_check_mem function in funcs.c in file before 5.23, as used in the Fileinfo component in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5, mishandles continuation-level jumps, which allows context-dependent attackers to cause a denial of service (buffer overflow and application crash) or possibly execute arbitrary code via a crafted magic file.
References: https://ubuntu.com/security/CVE-2015-8865, https://ubuntu.com/security/notices/USN-2952-1, http://www.openwall.com/lists/oss-security/2016/04/11/7, https://ubuntu.com/security/notices/USN-2984-1, https://ubuntu.com/security/notices/USN-3686-1, https://ubuntu.com/security/notices/USN-3686-2, https://www.cve.org/CVERecord?id=CVE-2015-8865
Affected packages
Package
Name: file
Purl: pkg:deb/ubuntu/file@1:5.14-2ubuntu3.4?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
