CVE-2014-9652

Publication date 8 January 2015

Last updated 24 July 2024


Ubuntu priority

The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file.

Status

Package Ubuntu Release Status
file 14.10 utopic
Fixed 1:5.19-1ubuntu1.2
14.04 LTS trusty
Fixed 1:5.14-2ubuntu3.3
12.04 LTS precise
Fixed 5.09-2ubuntu0.6
10.04 LTS lucid
Not affected
php5 14.10 utopic
Fixed 5.5.12+dfsg-2ubuntu4.2
14.04 LTS trusty
Fixed 5.5.9+dfsg-1ubuntu4.6
12.04 LTS precise
Not affected
10.04 LTS lucid
Not affected

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
file
php5

References

Related Ubuntu Security Notices (USN)

Other references