First published: Thu Jun 14 2018(Updated: )
Alexander Cherepanov discovered that file incorrectly handled a large number of notes. An attacker could use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-9620) Alexander Cherepanov discovered that file incorrectly handled certain long strings. An attacker could use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-9621) Alexander Cherepanov discovered that file incorrectly handled certain malformed ELF files. An attacker could use this issue to cause a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-9653) It was discovered that file incorrectly handled certain magic files. An attacker could use this issue with a specially crafted magic file to cause a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 14.04 LTS. (CVE-2015-8865) It was discovered that file incorrectly handled certain malformed ELF files. An attacker could use this issue to cause a denial of service. (CVE-2018-10360)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/file | <1:5.32-2ubuntu0.1 | 1:5.32-2ubuntu0.1 |
=18.04 | ||
All of | ||
ubuntu/libmagic1 | <1:5.32-2ubuntu0.1 | 1:5.32-2ubuntu0.1 |
=18.04 | ||
All of | ||
ubuntu/file | <1:5.32-1ubuntu0.1 | 1:5.32-1ubuntu0.1 |
=17.10 | ||
All of | ||
ubuntu/libmagic1 | <1:5.32-1ubuntu0.1 | 1:5.32-1ubuntu0.1 |
=17.10 | ||
All of | ||
ubuntu/file | <1:5.25-2ubuntu1.1 | 1:5.25-2ubuntu1.1 |
=16.04 | ||
All of | ||
ubuntu/libmagic1 | <1:5.25-2ubuntu1.1 | 1:5.25-2ubuntu1.1 |
=16.04 | ||
All of | ||
ubuntu/file | <1:5.14-2ubuntu3.4 | 1:5.14-2ubuntu3.4 |
=14.04 | ||
All of | ||
ubuntu/libmagic1 | <1:5.14-2ubuntu3.4 | 1:5.14-2ubuntu3.4 |
=14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The severity of USN-3686-1 is moderate.
USN-3686-1 affects Ubuntu 14.04 LTS by causing a denial of service.
The remedy for file vulnerabilities in Ubuntu 18.04 is to update the 'file' package to version 1:5.32-2ubuntu0.1.
USN-3686-1 affects libmagic1 in Ubuntu 17.10 by handling certain long strings incorrectly.
You can get more information about USN-3686-1 on the Ubuntu official website using the reference links provided.