First published: Tue Jul 17 2012(Updated: )
file before 5.11 and libmagic allow remote attackers to cause a denial of service (crash) via a crafted Composite Document File (CDF) file that triggers (1) an out-of-bounds read or (2) an invalid pointer dereference.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Christos Zoulas file | <=5.10 | |
Tim Robbins Libmagic |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1571 has a high severity rating due to its potential to cause a denial of service through a crafted Composite Document File.
To fix CVE-2012-1571, upgrade the file command to version 5.11 or later.
CVE-2012-1571 affects file versions before 5.11 and libmagic without a specified version.
Yes, CVE-2012-1571 can be exploited by remote attackers through specially crafted CDF files.
CVE-2012-1571 includes an out-of-bounds read and an invalid pointer dereference.