CVE-2012-1571: Buffer Overflow
Published Jul 17, 2012
·Updated
file before 5.11 and libmagic allow remote attackers to cause a denial of service (crash) via a crafted Composite Document File (CDF) file that triggers (1) an out-of-bounds read or (2) an invalid pointer dereference.
Affected Software
2 affected components
Christos Zoulas file<=5.10
Tim Robbins Libmagic
Remediation
Patch Available
Event History
Jul 17, 2012
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:55 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2012-1571?
CVE-2012-1571 has a high severity rating due to its potential to cause a denial of service through a crafted Composite Document File.
2
How do I fix CVE-2012-1571?
To fix CVE-2012-1571, upgrade the file command to version 5.11 or later.
3
What versions are affected by CVE-2012-1571?
CVE-2012-1571 affects file versions before 5.11 and libmagic without a specified version.
4
Can CVE-2012-1571 be exploited remotely?
Yes, CVE-2012-1571 can be exploited by remote attackers through specially crafted CDF files.
5
What types of vulnerabilities does CVE-2012-1571 include?
CVE-2012-1571 includes an out-of-bounds read and an invalid pointer dereference.