Boletines de Vulnerabilidades

DSA-2868 php5 - denial of service

   
Software afectado Debian
 
It was discovered that file, a file type classification tool, contains aflaw in the handling of indirect magic rules in the libmagic library,which leads to an infinite recursion when trying to determine the filetype of certain files. The Common Vulnerabilities and Exposures projectID CVE-2014-1943 has been assigned to identify this flaw. Additionally,other well-crafted files might result in long computation times (whileusing 100% CPU) and overlong results.

More info:

http://www.debian.org/security/2014/dsa-2868