CVE-2014-8117: Medium severity file project file vulnerability
Published Dec 17, 2014
·Updated
softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors.
Affected Software
7 affected components
File Project File<=5.20
FreeBSD FreeBSD
Mageia Mageia=4.0
Canonical Ubuntu Linux=10.04
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=14.10
Remediation
Event History
Dec 17, 2014
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8117?
CVE-2014-8117 has a severity rating that indicates it can lead to denial of service due to uncontrolled recursion.
2
How do I fix CVE-2014-8117?
To fix CVE-2014-8117, upgrade to a version of the file command that is higher than 5.20.
3
What systems are affected by CVE-2014-8117?
CVE-2014-8117 affects file versions before 5.21 and various versions of FreeBSD and Ubuntu Linux.
4
What type of attack does CVE-2014-8117 involve?
CVE-2014-8117 involves a denial of service attack that can cause high CPU consumption or system crashes.
5
Is CVE-2014-8117 exploitable by remote attackers?
Yes, CVE-2014-8117 can be exploited by remote attackers through unspecified vectors to impact system resources.