The ELF parser in file 5.16 through 5.21 allows remote attackers to cause a denial of service via a long string.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade file | Aug 30, 2017 | Jan 21, 2015 |
| Debian | — | Upgrade file | Jul 30, 2024 | Jan 21, 2015 |
| Gentoo Linux | — | Upgrade sys-apps/file. | Oct 30, 2017 | Jan 21, 2015 |
| Suse | — | Upgrade file-develUpgrade fileUpgrade libmagic1-32bitUpgrade libmagic1Upgrade file-magicUpgrade python-magic | Nov 22, 2017 | Jan 21, 2015 |
| Ubuntu | — | Upgrade libmagic1Upgrade file | Jun 27, 2018 | Jan 21, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub