Debian Security Advisory
DLA-86-1 file -- LTS security update
- Date Reported:
- 12 Nov 2014
- Affected Packages:
- file
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 768806.
In Mitre's CVE dictionary: CVE-2014-3710. - More information:
-
Francisco Alonso of Red Hat Product Security found an issue in the file utility: when checking ELF files, note headers are incorrectly checked, thus potentially allowing attackers to cause a denial of service (out-of-bounds read and application crash) by supplying a specially crafted ELF file.
For the long-term stable distribution (squeeze-lts), this problem has been fixed in version 5.04-5+squeeze8.