Mike Frysinger discovered that the file awk script detector used multiple wildcard with unlimited repetitions. An attacker could use this issue to cause file to consume resources, resulting in a denial of service. (CVE-2013-7345)
Francisco Alonso discovered that file incorrectly handled certain CDF documents. A attacker could use this issue to cause file to hang or crash, resulting in a denial of service. (CVE-2014-0207, CVE-2014-3478, CVE-2014-3479, CVE-2014-3480, CVE-2014-3487)
Jan Kaluža discovered that file did not properly restrict the amount of data read during regex searches. An attacker could use this issue to cause file to consume resources, resulting in a denial of service. (CVE-2014-3538)
{ "availability": "No subscription required", "binaries": [ { "binary_version": "1:5.14-2ubuntu3.1", "binary_name": "file" }, { "binary_version": "1:5.14-2ubuntu3.1", "binary_name": "file-dbg" }, { "binary_version": "1:5.14-2ubuntu3.1", "binary_name": "libmagic-dev" }, { "binary_version": "1:5.14-2ubuntu3.1", "binary_name": "libmagic1" }, { "binary_version": "1:5.14-2ubuntu3.1", "binary_name": "python-magic" }, { "binary_version": "1:5.14-2ubuntu3.1", "binary_name": "python3-magic" } ] }