Bugzilla – Bug 753303
VUL-0: CVE-2012-1571: file crashes due to malformed CDF files
Last modified: 2021-08-31 12:07:01 UTC
Your friendly security team received the following report via oss-security. Please respond ASAP. The issue is public. CVE-2012-1571 Specially crafted CDF files could crash the "file" program (out of bounds heap buffer read) https://github.com/glensc/file/commit/1859fdb4e67c49c463c4e0078054335cd46ba295 https://github.com/glensc/file/commit/1aec04dbf8a24b8a6ba64c4f74efa0628e36db0b http://mx.gw.com/pipermail/file/2012/000914.html http://www.openwall.com/lists/oss-security/2012/02/20/7 http://www.debian.org/security/2012/dsa-2422 http://mx.gw.com/pipermail/file/2012/000915.html http://mx.gw.com/pipermail/file/2012/000916.html https://bugzilla.redhat.com/show_bug.cgi?id=805197
Does there exist any information on the version? Does the upstream author know about this?
Btw: It would help a lot if the text of Christos would be cited in the initial message as using a lot of URL's without any specific information isn't very pleased, is it?
IMHO ther are more changes between 5.10 and 5.11 as it seems that changes from e.g. cdf.h are missed in the cited githup commits.
Created attachment 482364 [details] file-CVE-2012-1571.patch IMHO this is the full patch about CVE-2012-1571
In the package file of SLES11, SLES11-SP1, SLES11-SP2 nor in SLES10 upto SLES10-SP4 is not CDF support included.
For 11.4 see request #110412 for 12.1 see request #110410
bugbot adjusting priority
This is an autogenerated message for OBS integration: This bug (753303) was mentioned in https://build.opensuse.org/request/show/110835 Factory / file
openSUSE-SU-2012:0488-1: An update that fixes one vulnerability is now available. Category: security (low) Bug References: 753303 CVE References: CVE-2012-1571 Sources used: openSUSE 12.1 (src): file-5.08-7.4.1, python-magic-5.08-7.4.1 openSUSE 11.4 (src): file-5.04-13.1, python-magic-5.04-13.1
released
This is an autogenerated message for OBS integration: This bug (753303) was mentioned in https://build.opensuse.org/request/show/130497 Evergreen:11.2 / file https://build.opensuse.org/request/show/130498 Evergreen:11.2 / python-magic
This is an autogenerated message for OBS integration: This bug (753303) was mentioned in https://build.opensuse.org/request/show/131214 Evergreen:11.2 / file https://build.opensuse.org/request/show/131215 Evergreen:11.2 / python-magic