CVE-2014-2270
UnknownEPSS 4.33%
Last modified
CVE-2014-2270 is a vulnerability of currently unknown severity. softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.. EPSS estimates a 4.33% chance of exploitation in the next 30 days.
Description
softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| File Project | File | < 5.17 |
| Php | Php | < 5.4.26 |
| Php | Php | >= 5.5.0, < 5.5.10 |
| Debian | Debian Linux | 6.0 |
| Debian | Debian Linux | 7.0 |
| Debian | Debian Linux | 8.0 |
| Canonical | Ubuntu Linux | 10.04 |
| Canonical | Ubuntu Linux | 12.04 |
| Canonical | Ubuntu Linux | 12.10 |
| Canonical | Ubuntu Linux | 13.10 |
| Opensuse | Opensuse | 11.4 |
| Opensuse | Opensuse | 12.3 |
| Opensuse | Opensuse | 13.1 |
References
- http://bugs.gw.com/view.php?id=313Broken Link, Patch
- http://lists.opensuse.org/opensuse-updates/2014-03/msg00034.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-03/msg00037.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-03/msg00084.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1765.htmlThird Party Advisory
- http://seclists.org/oss-sec/2014/q1/473Mailing List, Patch, Third Party Advisory
- http://seclists.org/oss-sec/2014/q1/504Mailing List, Patch, Third Party Advisory
- http://seclists.org/oss-sec/2014/q1/505Mailing List, Patch, Third Party Advisory
- http://support.apple.com/kb/HT6443Third Party Advisory
- http://www.debian.org/security/2014/dsa-2873Third Party Advisory
- http://www.php.net/ChangeLog-5.phpRelease Notes, Vendor Advisory
- http://www.ubuntu.com/usn/USN-2162-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2163-1Third Party Advisory
- https://github.com/file/file/commit/447558595a3650db2886cd2f416ad0beba965801Patch, Third Party Advisory
- https://security.gentoo.org/glsa/201503-08Third Party Advisory
- http://bugs.gw.com/view.php?id=313Broken Link, Patch
- http://lists.opensuse.org/opensuse-updates/2014-03/msg00034.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-03/msg00037.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-03/msg00084.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1765.htmlThird Party Advisory
- http://seclists.org/oss-sec/2014/q1/473Mailing List, Patch, Third Party Advisory
- http://seclists.org/oss-sec/2014/q1/504Mailing List, Patch, Third Party Advisory
- http://seclists.org/oss-sec/2014/q1/505Mailing List, Patch, Third Party Advisory
- http://support.apple.com/kb/HT6443Third Party Advisory
- http://www.debian.org/security/2014/dsa-2873Third Party Advisory
- http://www.php.net/ChangeLog-5.phpRelease Notes, Vendor Advisory
- http://www.ubuntu.com/usn/USN-2162-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2163-1Third Party Advisory
- https://github.com/file/file/commit/447558595a3650db2886cd2f416ad0beba965801Patch, Third Party Advisory
- https://security.gentoo.org/glsa/201503-08Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-2270?
softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.
How severe is CVE-2014-2270?
Severity scoring for CVE-2014-2270 is pending analysis. The EPSS model estimates a 4.33% probability of exploitation in the next 30 days.
How do I fix CVE-2014-2270?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2014-2270?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
