CVE-2014-3538
Publication date 3 July 2014
Last updated 24 July 2024
Ubuntu priority
file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7345.
Status
Package | Ubuntu Release | Status |
---|---|---|
file | 14.04 LTS trusty |
Fixed 1:5.14-2ubuntu3.1
|
Notes
Patch details
Package | Patch details |
---|---|
file |
References
Related Ubuntu Security Notices (USN)
- USN-2278-1
- file vulnerabilities
- 15 July 2014