CVE-2013-7345
Publication date 24 March 2014
Last updated 24 July 2024
Ubuntu priority
The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses multiple wildcards with unlimited repetitions, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted ASCII file that triggers a large amount of backtracking, as demonstrated via a file with many newline characters.
Status
Package | Ubuntu Release | Status |
---|---|---|
file | 14.04 LTS trusty |
Fixed 1:5.14-2ubuntu3.1
|
Notes
Patch details
Package | Patch details |
---|---|
file |
|
References
Related Ubuntu Security Notices (USN)
- USN-2278-1
- file vulnerabilities
- 15 July 2014