CVE-2013-7345

Published: 24 March 2014

The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses multiple wildcards with unlimited repetitions, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted ASCII file that triggers a large amount of backtracking, as demonstrated via a file with many newline characters.

Priority

Low

Status

Package Release Status
file
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 14.04 ESM (Trusty Tahr)
Released (1:5.14-2ubuntu3.1)
Patches:
Vendor: http://www.debian.org/security/2014/dsa-2873
Upstream: https://github.com/file/file/commit/ef2329cf71acb59204dd981e2c6cce6c81fe467c