Debian Security Advisory
DSA-3072-1 file -- security update
- Date Reported:
- 11 Nov 2014
- Affected Packages:
- file
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 768806.
In Mitre's CVE dictionary: CVE-2014-3710. - More information:
-
Francisco Alonso of Red Hat Product Security found an issue in the file utility: when checking ELF files, note headers are incorrectly checked, thus potentially allowing attackers to cause a denial of service (out-of-bounds read and application crash) by supplying a specially crafted ELF file.
For the stable distribution (wheezy), this problem has been fixed in version 5.11-2+deb7u6.
For the upcoming stable distribution (jessie), this problem will be fixed soon.
For the unstable distribution (sid), this problem has been fixed in version 1:5.20-2.
We recommend that you upgrade your file packages.