---
title: "CVE-2014-2270\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2014-2270?format=md
keywords: index, follow
---

# CVE-2014-2270

Publication date 14 March 2014

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

softmagic.c in file before 5.17 and libmagic allows context-dependent
attackers to cause a denial of service (out-of-bounds memory access and
crash) via crafted offsets in the softmagic of a PE executable.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2014-2270?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| file | 13.10 saucy | Fixed 5.11-2ubuntu4.2 |
| 12.10 quantal | Fixed 5.11-2ubuntu0.2 |
| 12.04 LTS precise | Fixed 5.09-2ubuntu0.3 |
| 10.04 LTS lucid | Fixed 5.03-5ubuntu1.2 |
| php5 | 13.10 saucy | Fixed 5.5.3+dfsg-1ubuntu2.3 |
| 12.10 quantal | Fixed 5.4.6-1ubuntu1.8 |
| 12.04 LTS precise | Fixed 5.3.10-1ubuntu3.11 |
| 10.04 LTS lucid | Fixed 5.3.2-1ubuntu4.24 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2014-2270?format=md#patch-details)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

see regression fix in DSA-2873-2
The regression in the debian package is caused by a fix for
a different issue which does not seem to have a CVE number:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=703993
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742262 (file regression 1)
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742265 (file regression 2)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| file | * Upstream:   [4475585](https://github.com/file/file/commit/447558595a3650db2886cd2f416ad0beba965801) * Upstream:   [70c65d2](https://github.com/file/file/commit/70c65d2e1841491f59168db1f905e8b14083fb1c) |
| php5 | * Upstream:   <http://git.php.net/?p=php-src.git;a=commitdiff;h=a33759fd275b32ed0bbe89796fe2953b3cb0b41f> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2270)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2014-2270)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2014-2270)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2014-2270)

### Related Ubuntu Security Notices (USN)

+ [USN-2163-1](https://usn.ubuntu.com/USN-2163-1)
+ PHP vulnerability
+ 7 April 2014

+ [USN-2162-1](https://usn.ubuntu.com/USN-2162-1)
+ file vulnerability
+ 7 April 2014

### Other references

* <http://seclists.org/oss-sec/2014/q1/473>
* <https://www.cve.org/CVERecord?id=CVE-2014-2270>
