CVE-2012-1571

file before 5.11 and libmagic allow remote attackers to cause a denial of service (crash) via a crafted Composite Document File (CDF) file that triggers (1) an out-of-bounds read or (2) an invalid pointer dereference.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 50%
VendorProductVersion
christos_zoulasfile
𝑥
≤ 5.10
tim_robbinslibmagic
*
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
file
bullseye (security)
1:5.39-3+deb11u1
fixed
bullseye
1:5.39-3+deb11u1
fixed
bookworm
1:5.44-3
fixed
sid
1:5.45-3
fixed
trixie
1:5.45-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
file
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
Fixed 5.09-2ubuntu0.2
released
oneiric
ignored
natty
ignored
maverick
ignored
lucid
Fixed 5.03-5ubuntu1.1
released
hardy
ignored