Alerts This Week
Warning Icon 1 541
Alerts This Week
Warning Icon 1 541

Ubuntu 20.04: USN-4032-1 Important: Image Processing Denial of Service

Ubuntu Large Esm H500
The file utility could be made to crash if it opened a speciallycrafted file.
=========================================================================Ubuntu Security Notice USN-3412-1
September 07, 2017

file vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 17.04

Summary:

The file utility could be made to crash if it opened a specially
crafted file.

Software Description:
- file: Tool to determine file types

Details:

Thomas Jarosch discovered that file incorrectly handled certain ELF
files. An attacker could use this to cause file to crash, resulting
in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 17.04:
  file                            1:5.29-3ubuntu0.1
  libmagic1                       1:5.29-3ubuntu0.1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-3412-1
  CVE-2017-1000249

Package Information:
  https://launchpad.net/ubuntu/+source/file/1:5.29-3ubuntu0.1

Ubuntu 20.04: USN-4032-1 Important: Image Processing Denial of Service

ubuntu
Calendar Grey September 7, 2017
Dist Ubuntu Esm H88
Critical notification regarding a vulnerability in Ubuntu 17.04's file handling that could result in service disruption through specially crafted files. Update is accessible immediately.
The file utility could be made to crash if it opened a speciallycrafted file.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 17.04: file 1:5.29-3ubuntu0.1 libmagic1 1:5.29-3ubuntu0.1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-3412-1

CVE-2017-1000249

Severity
important
Lowest
Low
Medium
High
Critical

September 07, 2017

Package Information

https://launchpad.net/ubuntu/+source/file/1:5.29-3ubuntu0.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here