The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses multiple wildcards with unlimited repetitions, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted ASCII file that triggers a large amount of backtracking, as demonstrated via a file with many newline characters.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade php | Aug 30, 2017 | Mar 24, 2014 |
| Apple Osx Apachemodphp | — | Upgrade macOS to the latest version | Sep 22, 2014 | Mar 24, 2014 |
| Apple Osx Note | — | Upgrade macOS to the latest versionApply OS X security update 2014-004 | Aug 28, 2015 | Mar 24, 2014 |
| Centos_linux | — | Upgrade php-gdUpgrade php-bcmathUpgrade php-dbaUpgrade php-pdoUpgrade php-mysqlUpgrade php-pspellUpgrade php-embeddedUpgrade php-enchantUpgrade php-soapUpgrade php-intlUpgrade php-odbcUpgrade php-processUpgrade php-pgsqlUpgrade php-mbstringUpgrade php-cliUpgrade php-develUpgrade php-recodeUpgrade php-snmpUpgrade php-ldapUpgrade php-mysqlndUpgrade phpUpgrade php-fpmUpgrade php-commonUpgrade php-xmlrpcUpgrade php-xml | Dec 1, 2016 | Mar 24, 2014 |
| Debian | — | Upgrade php5Upgrade file | Jul 30, 2024 | Mar 24, 2014 |
| Freebsd | — | Upgrade FreeBSD | Dec 10, 2025 | Aug 11, 2016 |
| Gentoo Linux | — | Upgrade dev-lang/php.Upgrade sys-apps/file. | Oct 30, 2017 | Mar 24, 2014 |
| Oracle_linux | — | Upgrade php-fpmUpgrade php-intlUpgrade php-odbcUpgrade php-develUpgrade phpUpgrade php-pdoUpgrade php-ldapUpgrade php-bcmathUpgrade php-pgsqlUpgrade php-commonUpgrade php-mysqlUpgrade php-gdUpgrade php-snmpUpgrade php-processUpgrade php-xmlrpcUpgrade php-recodeUpgrade php-soapUpgrade php-embeddedUpgrade php-pspellUpgrade php-cliUpgrade php-mbstringUpgrade php-enchantUpgrade php-xmlUpgrade php-dbaUpgrade php-mysqlnd | Oct 16, 2024 | Mar 23, 2014 |
| Php | — | Upgrade to PHP version 5.5.11Upgrade to PHP version 5.4.27 | Nov 14, 2022 | Mar 24, 2014 |
| Suse | — | Upgrade libmagic1-32bitUpgrade file-develUpgrade python-magicUpgrade libmagic1Upgrade libmagic-dataUpgrade file | Apr 7, 2014 | Mar 24, 2014 |
| Ubuntu | — | Upgrade fileUpgrade libmagic1 | Nov 8, 2024 | Mar 24, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub