Resource exhaustion in file - CVE-2014-8117
Published: April 1, 2016 / Updated: November 27, 2018
Vulnerability identifier: #VU3894
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-8117
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition.
The weakness exists due to resource exhaustion when softmagic.c in file before 5.21 does not properly limit recursion. A remote attacker can trigger CPU consumption and cause the service to crash.
The weakness exists due to resource exhaustion when softmagic.c in file before 5.21 does not properly limit recursion. A remote attacker can trigger CPU consumption and cause the service to crash.
Affected software
file
Gentoo Linux
php5 (Ubuntu package)
file (Alpine package)
Gentoo Linux
php5 (Ubuntu package)
file (Alpine package)
How to mitigate CVE-2014-8117
Install update from vendor's website.
file - update to 5.21
php5 (Ubuntu package) - addressed in versions 5.3.2-1ubuntu4.29, 5.3.10-1ubuntu3.17, 5.5.9+dfsg-1ubuntu4.7, 5.5.12+dfsg-2ubuntu4.3
file (Alpine package) - update to 5.22-r0
php5 (Ubuntu package) - addressed in versions 5.3.2-1ubuntu4.29, 5.3.10-1ubuntu3.17, 5.5.9+dfsg-1ubuntu4.7, 5.5.12+dfsg-2ubuntu4.3
file (Alpine package) - update to 5.22-r0