CVE-2013-7345: Medium severity Christos Zoulas file vulnerability
The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses multiple wildcards with unlimited repetitions, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted ASCII file that triggers a large amount of backtracking, as demonstrated via a file with many newline characters.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7345?
CVE-2013-7345 is classified as a denial of service vulnerability due to excessive CPU consumption.
How do I fix CVE-2013-7345?
To mitigate CVE-2013-7345, update the affected file utility to version 5.15 or later.
What software is affected by CVE-2013-7345?
CVE-2013-7345 affects the 'file' utility versions prior to 5.15 and specific versions of PHP on various Debian Linux distributions.
What type of attack does CVE-2013-7345 enable?
CVE-2013-7345 allows attackers to cause a denial of service by using crafted ASCII files that exploit the vulnerable regular expression.
When was CVE-2013-7345 reported?
CVE-2013-7345 was reported in 2013 and affects several versions of file and PHP utilities.