Bug 910253 (CVE-2014-8117) - VUL-0: CVE-2014-8117: denial of service issue (resource consumption)
Summary: VUL-0: CVE-2014-8117: denial of service issue (resource consumption)
Status: RESOLVED FIXED
Alias: CVE-2014-8117
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Dr. Werner Fink
QA Contact: Security Team bot
URL:
Whiteboard: CVSSv2:NVD:CVE-2014-8116:5.0:(AV:N/A...
Keywords:
Depends on:
Blocks:
 
Reported: 2014-12-16 09:38 UTC by Alexander Bergmann
Modified: 2020-09-18 12:55 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2014-12-16 09:38:37 UTC
Via rh#1174606:

CVE-2014-8117 was assigned to this issue.

Thomas Jarosch of Intra2net AG reported a denial of service issue (resource consumption) in the ELF parser used by file(1). Using file(1) on a specially-crafted ELF binary could lead to a denial of service (resource consumption).

Upstream fix:

https://github.com/file/file/commit/6f737ddfadb596d7d4a993f7ed2141ffd664a81c

Due to some regressions found when testing, the following commits are also required:

https://github.com/file/file/commit/8a905717660395b38ec4966493f6f1cf2f33946c
https://github.com/file/file/commit/90018fe22ff8b74a22fcd142225b0a00f3f12677
https://github.com/file/file/commit/6bf45271eb8e0e6577b92042ce2003ba998d1686

Refer also to rh#1171580 (CVE-2014-8116).

Acknowledgements:

Red Hat would like to thank Thomas Jarosch of Intra2net AG for reporting this issue.
Comment 1 Alexander Bergmann 2014-12-16 09:39:42 UTC
See bug 910252 for CVE-2014-8116.
Comment 2 Dr. Werner Fink 2014-12-16 09:54:52 UTC
Please tell us *which* versions are affected as well as *please* provide an reproducer.
Comment 3 Swamp Workflow Management 2014-12-16 23:00:23 UTC
bugbot adjusting priority
Comment 4 Bernhard Wiedemann 2014-12-17 14:00:13 UTC
This is an autogenerated message for OBS integration:
This bug (910253) was mentioned in
https://build.opensuse.org/request/show/265566 Factory / file
Comment 5 Dr. Werner Fink 2014-12-18 12:33:03 UTC
Ping?
Comment 6 Bernhard Wiedemann 2014-12-19 10:00:15 UTC
This is an autogenerated message for OBS integration:
This bug (910253) was mentioned in
https://build.opensuse.org/request/show/265888 13.2 / file
https://build.opensuse.org/request/show/265889 13.1 / file
Comment 8 Swamp Workflow Management 2014-12-27 21:07:22 UTC
openSUSE-SU-2014:1721-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 910252,910253
CVE References: CVE-2014-8116,CVE-2014-8117
Sources used:
openSUSE 13.1 (src):    file-5.15-4.28.1, python-magic-5.15-4.28.1
Comment 9 Swamp Workflow Management 2014-12-30 13:06:21 UTC
SUSE-SU-2014:1730-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 910252,910253
CVE References: CVE-2014-8116,CVE-2014-8117
Sources used:
SUSE Linux Enterprise Software Development Kit 12 (src):    file-5.19-9.1, python-magic-5.19-9.1
SUSE Linux Enterprise Server 12 (src):    file-5.19-9.1
SUSE Linux Enterprise Desktop 12 (src):    file-5.19-9.1
Comment 10 Dr. Werner Fink 2015-02-13 13:19:20 UTC
Also here ... file 4.24 and below do not do a recursion in src/softmagic.c that IMHO there is no vulnerability.  If you think this is not correct then please provide an example!
Comment 11 Johannes Segitz 2015-02-17 17:10:39 UTC
all updates released
Comment 12 Bernhard Wiedemann 2015-02-18 15:00:16 UTC
This is an autogenerated message for OBS integration:
This bug (910253) was mentioned in
https://build.opensuse.org/request/show/286645 13.1 / file
https://build.opensuse.org/request/show/286646 13.2 / file
Comment 14 Swamp Workflow Management 2017-11-22 20:12:11 UTC
SUSE-SU-2017:3048-1: An update that solves 5 vulnerabilities and has three fixes is now available.

Category: security (moderate)
Bug References: 1009966,1063269,910252,910253,913650,913651,917152,996511
CVE References: CVE-2014-8116,CVE-2014-8117,CVE-2014-9620,CVE-2014-9621,CVE-2014-9653
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP3 (src):    file-5.22-10.3.1, python-magic-5.22-10.3.1
SUSE Linux Enterprise Software Development Kit 12-SP2 (src):    file-5.22-10.3.1, python-magic-5.22-10.3.1
SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src):    file-5.22-10.3.1
SUSE Linux Enterprise Server 12-SP3 (src):    file-5.22-10.3.1
SUSE Linux Enterprise Server 12-SP2 (src):    file-5.22-10.3.1
SUSE Linux Enterprise Desktop 12-SP3 (src):    file-5.22-10.3.1
SUSE Linux Enterprise Desktop 12-SP2 (src):    file-5.22-10.3.1
SUSE Container as a Service Platform ALL (src):    file-5.22-10.3.1
OpenStack Cloud Magnum Orchestration 7 (src):    file-5.22-10.3.1
Comment 15 Swamp Workflow Management 2017-11-23 23:08:29 UTC
openSUSE-SU-2017:3067-1: An update that solves 5 vulnerabilities and has three fixes is now available.

Category: security (moderate)
Bug References: 1009966,1063269,910252,910253,913650,913651,917152,996511
CVE References: CVE-2014-8116,CVE-2014-8117,CVE-2014-9620,CVE-2014-9621,CVE-2014-9653
Sources used:
openSUSE Leap 42.3 (src):    file-5.22-10.1, python-magic-5.22-10.1
openSUSE Leap 42.2 (src):    file-5.22-7.3.1, python-magic-5.22-7.3.1