Debian Security Advisory

DLA-86-1 file -- LTS security update

Date Reported:
12 Nov 2014
Affected Packages:
file
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 768806.
In Mitre's CVE dictionary: CVE-2014-3710.
More information:

Francisco Alonso of Red Hat Product Security found an issue in the file utility: when checking ELF files, note headers are incorrectly checked, thus potentially allowing attackers to cause a denial of service (out-of-bounds read and application crash) by supplying a specially crafted ELF file.

For the long-term stable distribution (squeeze-lts), this problem has been fixed in version 5.04-5+squeeze8.