CVE-2014-2270: Buffer Overflow
softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2270?
CVE-2014-2270 has been rated as a denial of service vulnerability due to out-of-bounds memory access.
How do I fix CVE-2014-2270?
To fix CVE-2014-2270, update to the latest versions of the affected software, ensuring you are beyond the specified vulnerable versions.
What software is affected by CVE-2014-2270?
CVE-2014-2270 affects the file utility before version 5.17, PHP versions prior to 5.4.26 and between 5.5.0 and 5.5.10, as well as several versions of Debian and Ubuntu.
What type of attack exploits CVE-2014-2270?
CVE-2014-2270 can be exploited by context-dependent attackers causing a denial of service through crafted offsets in the softmagic of a PE executable.
Is CVE-2014-2270 a critical vulnerability?
While CVE-2014-2270 is not classified as critical, it does pose a significant risk due to its potential to disrupt services.