file: multiple denial of service issues (resource consumption)
Published Dec 17, 2014
5.0
MEDIUMCVSS 2.0
EPSS 4.43%
Description
The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large number of (1) program or (2) section headers or (3) invalid capabilities.
Affected products
No data.
Configuration 1
- 5.20
- n/a
Configuration 3
- 10.04
- 12.04
- 14.04
- 14.10
No data.
Red Hat Enterprise Linux 6
file-0:5.04-30.el6
Fixed · RHSA-2016:0760
Red Hat Enterprise Linux 7
file-0:5.11-31.el7
Fixed · RHSA-2015:2155
Red Hat Enterprise Linux 5
file
Will not fix
Red Hat Enterprise Linux 5
php
Not affected
Red Hat Enterprise Linux 5
php53
Not affected
Red Hat Enterprise Linux 6
php
Not affected
Red Hat Enterprise Linux 7
php
Not affected
Red Hat Software Collections
php54-php
Not affected
Red Hat Software Collections
php55-php
Not affected
Red Hat Software Collections
rh-php56-php
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | file-0:5.04-30.el6 | Fixed | RHSA-2016:0760 |
| Red Hat Enterprise Linux 7 | file-0:5.11-31.el7 | Fixed | RHSA-2015:2155 |
| Red Hat Enterprise Linux 5 | file | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | php | Not affected | n/a |
| Red Hat Enterprise Linux 5 | php53 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | php | Not affected | n/a |
| Red Hat Enterprise Linux 7 | php | Not affected | n/a |
| Red Hat Software Collections | php54-php | Not affected | n/a |
| Red Hat Software Collections | php55-php | Not affected | n/a |
| Red Hat Software Collections | rh-php56-php | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (18)
- http://advisories.mageia.org/MGASA-2015-0040.html x_refsource_CONFIRMThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0760.html vendor-advisoryx_refsource_REDHAT
- http://seclists.org/oss-sec/2014/q4/1056 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://secunia.com/advisories/61944 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/62081 third-party-advisoryx_refsource_SECUNIA
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html x_refsource_CONFIRM
- http://www.securityfocus.com/bid/71700 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1031344 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-2494-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2014-8116 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1171580 Issue Tracking
- https://github.com/file/file/blob/00cef282a902a4a6709bbbbb933ee397768caa38/ChangeLog x_refsource_CONFIRMIssue TrackingPatch
- https://github.com/file/file/commit/b4c01141e5367f247b84dcaf6aefbb4e741842b8 x_refsource_CONFIRMIssue TrackingPatch
- https://github.com/file/file/commit/d7cdad007c507e6c79f51f058dd77fab70ceb9f6 x_refsource_CONFIRMIssue TrackingPatch
- https://nvd.nist.gov/vuln/detail/CVE-2014-8116
- https://www.cve.org/CVERecord?id=CVE-2014-8116
- https://www.freebsd.org/security/advisories/FreeBSD-SA-14:28.file.asc vendor-advisoryx_refsource_FREEBSDVendor Advisory
Change history (0)
No recorded changes yet.