USN-3686-1
Dashboard / Vulnerabilities / USN-3686-1
USN-3686-1
Summary: file vulnerabilities
Details: Alexander Cherepanov discovered that file incorrectly handled a large number of notes. An attacker could use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-9620) Alexander Cherepanov discovered that file incorrectly handled certain long strings. An attacker could use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-9621) Alexander Cherepanov discovered that file incorrectly handled certain malformed ELF files. An attacker could use this issue to cause a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-9653) It was discovered that file incorrectly handled certain magic files. An attacker could use this issue with a specially crafted magic file to cause a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 14.04 LTS. (CVE-2015-8865) It was discovered that file incorrectly handled certain malformed ELF files. An attacker could use this issue to cause a denial of service. (CVE-2018-10360)
References: https://ubuntu.com/security/notices/USN-3686-1, https://ubuntu.com/security/CVE-2014-9620, https://ubuntu.com/security/CVE-2014-9621, https://ubuntu.com/security/CVE-2014-9653, https://ubuntu.com/security/CVE-2015-8865, https://ubuntu.com/security/CVE-2018-10360
Affected packages
Package
Name: file
Purl: pkg:deb/ubuntu/file@1:5.14-2ubuntu3.4?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
