CVE-2013-7345
24.03.2014, 16:31
The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses multiple wildcards with unlimited repetitions, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted ASCII file that triggers a large amount of backtracking, as demonstrated via a file with many newline characters.Enginsight
| Vendor | Product | Version |
|---|---|---|
| christos_zoulas | file | 𝑥 < 5.15 |
| php | php | 5.4.0 ≤ 𝑥 < 5.4.27 |
| php | php | 5.5.0 ≤ 𝑥 < 5.5.11 |
| debian | debian_linux | 6.0 |
| debian | debian_linux | 7.0 |
| debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References