Bugzilla – Bug 917152
VUL-1: CVE-2014-9653 file: malformed elf file causes access to uninitialized memory
Last modified: 2019-03-25 15:52:01 UTC
A malformed elf file can cause file urility to access invalid memory. Upstream fixes: https://github.com/file/file/commit/445c8fb0ebff85195be94cd9f7e1df89cade5c7f https://github.com/file/file/commit/e96f86b5311572be1360ee0bb05d4926f8df3189 References: https://bugzilla.redhat.com/show_bug.cgi?id=1190116 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9653 http://seclists.org/oss-sec/2015/q1/433 http://people.canonical.com/~ubuntu-security/cve/2014/CVE-2014-9653.html
bugbot adjusting priority
This is an autogenerated message for OBS integration: This bug (917152) was mentioned in https://build.opensuse.org/request/show/286645 13.1 / file https://build.opensuse.org/request/show/286646 13.2 / file
SUSE-SU-2017:3048-1: An update that solves 5 vulnerabilities and has three fixes is now available. Category: security (moderate) Bug References: 1009966,1063269,910252,910253,913650,913651,917152,996511 CVE References: CVE-2014-8116,CVE-2014-8117,CVE-2014-9620,CVE-2014-9621,CVE-2014-9653 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP3 (src): file-5.22-10.3.1, python-magic-5.22-10.3.1 SUSE Linux Enterprise Software Development Kit 12-SP2 (src): file-5.22-10.3.1, python-magic-5.22-10.3.1 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src): file-5.22-10.3.1 SUSE Linux Enterprise Server 12-SP3 (src): file-5.22-10.3.1 SUSE Linux Enterprise Server 12-SP2 (src): file-5.22-10.3.1 SUSE Linux Enterprise Desktop 12-SP3 (src): file-5.22-10.3.1 SUSE Linux Enterprise Desktop 12-SP2 (src): file-5.22-10.3.1 SUSE Container as a Service Platform ALL (src): file-5.22-10.3.1 OpenStack Cloud Magnum Orchestration 7 (src): file-5.22-10.3.1
openSUSE-SU-2017:3067-1: An update that solves 5 vulnerabilities and has three fixes is now available. Category: security (moderate) Bug References: 1009966,1063269,910252,910253,913650,913651,917152,996511 CVE References: CVE-2014-8116,CVE-2014-8117,CVE-2014-9620,CVE-2014-9621,CVE-2014-9653 Sources used: openSUSE Leap 42.3 (src): file-5.22-10.1, python-magic-5.22-10.1 openSUSE Leap 42.2 (src): file-5.22-7.3.1, python-magic-5.22-7.3.1
(In reply to Swamp Workflow Management from comment #9) > openSUSE-SU-2017:3067-1: An update that solves 5 vulnerabilities and has > three fixes is now available. > > Category: security (moderate) > Bug References: 1009966,1063269,910252,910253,913650,913651,917152,996511 > CVE References: > CVE-2014-8116,CVE-2014-8117,CVE-2014-9620,CVE-2014-9621,CVE-2014-9653 > Sources used: > openSUSE Leap 42.3 (src): file-5.22-10.1, python-magic-5.22-10.1 > openSUSE Leap 42.2 (src): file-5.22-7.3.1, python-magic-5.22-7.3.1