CVE-2013-7345
24.03.2014, 16:31
The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses multiple wildcards with unlimited repetitions, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted ASCII file that triggers a large amount of backtracking, as demonstrated via a file with many newline characters.Enginsight
Vendor | Product | Version |
---|---|---|
christos_zoulas | file | 𝑥 < 5.15 |
php | php | 5.4.0 ≤ 𝑥 < 5.4.27 |
php | php | 5.5.0 ≤ 𝑥 < 5.5.11 |
debian | debian_linux | 6.0 |
debian | debian_linux | 7.0 |
debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References