oss-sec mailing list archives
Re: Re: CVE Request: file: crashes when checking softmagic for some corrupt PE executables
From: "mancha" <mancha1 () hush com>
Date: Wed, 05 Mar 2014 18:29:22 +0000
On Wed, 05 Mar 2014 17:08:17 +0000 cve-assign () mitre org wrote:
file can be made to crash when checking some corrupt PE executables, and so could be used to mount a denial of service for file, or an application using file/libmagic. http://bugs.gw.com/view.php?id=313 https://github.com/glensc/file/commit/447558595a3650db2886cdUse CVE-2014-2270.
CVE Assignment Team, et al. - The initial fix for this problem [1] had an off-by-one flaw that has since been corrected [2]. I am unsure of the policy regarding the issuance of new CVE identifiers associated with incomplete/flawed fixes associated with previously allocated CVEs. But, in this particular case file 5.17 shipped with [1] and not [2]. --mancha [1] https://github.com/file/file/commit/447558595a36 [2] https://github.com/file/file/commit/70c65d2e1841
Current thread:
- CVE Request: file: crashes when checking softmagic for some corrupt PE executables Salvatore Bonaccorso (Mar 03)
- Re: CVE Request: file: crashes when checking softmagic for some corrupt PE executables cve-assign (Mar 05)
- Re: Re: CVE Request: file: crashes when checking softmagic for some corrupt PE executables Salvatore Bonaccorso (Mar 05)
- Re: Re: CVE Request: file: crashes when checking softmagic for some corrupt PE executables Stuart Henderson (Mar 13)
- <Possible follow-ups>
- Re: Re: CVE Request: file: crashes when checking softmagic for some corrupt PE executables mancha (Mar 05)
- Re: CVE Request: file: crashes when checking softmagic for some corrupt PE executables cve-assign (Mar 05)