A buffer overflow was found in file, a file type classification tool, which may result in denial of service if a specially crafted file is processed. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5489-1
Upstream details at : https://access.redhat.com/errata/RHSA-2020:3344. CentOS Errata and Security Advisory 2020:3344 Important Upstream details at : https://access.redhat.com/errata/RHSA-2020:3344 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: 1843f66766dd4e3ec0481895eb214582b167995238898e2666b1dcb523e0a7a1 thunderbird-68.11.0-1.el7.centos.x86_64.rpm Source: ad6d42bca1ff78685b464bb05fab28a9ddedde5fc9c7a4a71de77fef45fedc6d thunderbird-68.11.0-1.el7.centos.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #
An update for file is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: file security update Advisory ID: RHSA-2020:2838-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:2838 Issue date: 2020-07-07 CVE Names: CVE-2018-10360 ==================================================================== 1. Summary: An update for file is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode EUS (v. 7.6) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6) - x86_64 Red Hat Enterprise Linux Server EUS (v. 7.6) - noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional EUS (v. 7.6) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7) - aarch64, noarch, ppc64le, s390x Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7) - aarch64, ppc64le, s390x 3. Description: The file command is used to identify a particular file according to the type of data the file contains. It can identify many different file types, including Executable and Linkable Format (ELF) binary files, system libraries, RPM packages, and different graphics formats. Security Fix(es): * file: out-of-bounds read via a crafted ELF file (CVE-2018-10360) Formore details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1590000 - CVE-2018-10360 file: out-of-bounds read via a crafted ELF file 6. Package List: Red Hat Enterprise Linux ComputeNode EUS (v. 7.6): Source: file-5.11-35.el7_6.1.src.rpm noarch: python-magic-5.11-35.el7_6.1.noarch.rpm x86_64: file-5.11-35.el7_6.1.x86_64.rpm file-debuginfo-5.11-35.el7_6.1.i686.rpm file-debuginfo-5.11-35.el7_6.1.x86_64.rpm file-libs-5.11-35.el7_6.1.i686.rpm file-libs-5.11-35.el7_6.1.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6): x86_64: file-debuginfo-5.11-35.el7_6.1.i686.rpm file-debuginfo-5.11-35.el7_6.1.x86_64.rpm file-devel-5.11-35.el7_6.1.i686.rpm file-devel-5.11-35.el7_6.1.x86_64.rpm file-static-5.11-35.el7_6.1.i686.rpm file-static-5.11-35.el7_6.1.x86_64.rpm Red Hat Enterprise Linux Server EUS (v. 7.6): Source: file-5.11-35.el7_6.1.src.rpm noarch: python-magic-5.11-35.el7_6.1.noarch.rpm ppc64: file-5.11-35.el7_6.1.ppc64.rpm file-debuginfo-5.11-35.el7_6.1.ppc.rpm file-debuginfo-5.11-35.el7_6.1.ppc64.rpm file-libs-5.11-35.el7_6.1.ppc.rpm file-libs-5.11-35.el7_6.1.ppc64.rpm ppc64le: file-5.11-35.el7_6.1.ppc64le.rpm file-debuginfo-5.11-35.el7_6.1.ppc64le.rpm file-libs-5.11-35.el7_6.1.ppc64le.rpm s390x: file-5.11-35.el7_6.1.s390x.rpm file-debuginfo-5.11-35.el7_6.1.s390.rpm file-debuginfo-5.11-35.el7_6.1.s390x.rpm file-libs-5.11-35.el7_6.1.s390.rpm file-libs-5.11-35.el7_6.1.s390x.rpm x86_64: file-5.11-35.el7_6.1.x86_64.rpm file-debuginfo-5.11-35.el7_6.1.i686.rpm file-debuginfo-5.11-35.el7_6.1.x86_64.rpm file-libs-5.11-35.el7_6.1.i686.rpm file-libs-5.11-35.el7_6.1.x86_64.rpm Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v.7): Source: file-5.11-35.el7_6.1.src.rpm aarch64: file-5.11-35.el7_6.1.aarch64.rpm file-debuginfo-5.11-35.el7_6.1.aarch64.rpm file-libs-5.11-35.el7_6.1.aarch64.rpm noarch: python-magic-5.11-35.el7_6.1.noarch.rpm ppc64le: file-5.11-35.el7_6.1.ppc64le.rpm file-debuginfo-5.11-35.el7_6.1.ppc64le.rpm file-libs-5.11-35.el7_6.1.ppc64le.rpm s390x: file-5.11-35.el7_6.1.s390x.rpm file-debuginfo-5.11-35.el7_6.1.s390.rpm file-debuginfo-5.11-35.el7_6.1.s390x.rpm file-libs-5.11-35.el7_6.1.s390.rpm file-libs-5.11-35.el7_6.1.s390x.rpm Red Hat Enterprise Linux Server Optional EUS (v. 7.6): ppc64: file-debuginfo-5.11-35.el7_6.1.ppc.rpm file-debuginfo-5.11-35.el7_6.1.ppc64.rpm file-devel-5.11-35.el7_6.1.ppc.rpm file-devel-5.11-35.el7_6.1.ppc64.rpm file-static-5.11-35.el7_6.1.ppc.rpm file-static-5.11-35.el7_6.1.ppc64.rpm ppc64le: file-debuginfo-5.11-35.el7_6.1.ppc64le.rpm file-devel-5.11-35.el7_6.1.ppc64le.rpm file-static-5.11-35.el7_6.1.ppc64le.rpm s390x: file-debuginfo-5.11-35.el7_6.1.s390.rpm file-debuginfo-5.11-35.el7_6.1.s390x.rpm file-devel-5.11-35.el7_6.1.s390.rpm file-devel-5.11-35.el7_6.1.s390x.rpm file-static-5.11-35.el7_6.1.s390.rpm file-static-5.11-35.el7_6.1.s390x.rpm x86_64: file-debuginfo-5.11-35.el7_6.1.i686.rpm file-debuginfo-5.11-35.el7_6.1.x86_64.rpm file-devel-5.11-35.el7_6.1.i686.rpm file-devel-5.11-35.el7_6.1.x86_64.rpm file-static-5.11-35.el7_6.1.i686.rpm file-static-5.11-35.el7_6.1.x86_64.rpm Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7): aarch64: file-debuginfo-5.11-35.el7_6.1.aarch64.rpm file-devel-5.11-35.el7_6.1.aarch64.rpm file-static-5.11-35.el7_6.1.aarch64.rpm ppc64le: file-debuginfo-5.11-35.el7_6.1.ppc64le.rpm file-devel-5.11-35.el7_6.1.ppc64le.rpm file-static-5.11-35.el7_6.1.ppc64le.rpm s390x: file-debuginfo-5.11-35.el7_6.1.s390.rpm file-debuginfo-5.11-35.el7_6.1.s390x.rpm file-devel-5.11-35.el7_6.1.s390.rpm file-devel-5.11-35.el7_6.1.s390x.rpm file-static-5.11-35.el7_6.1.s390.rpm file-static-5.11-35.el7_6.1.s390x.rpm These packages are GPG signedby Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2018-10360 https://access.redhat.com/security/updates/classification#low 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXwRNYNzjgjWX9erEAQgLixAAoMfaThaU1PnaQbMB8PzCUHCGclpashCN YNEOdttu0HQlDy5AW1S18Z4yjP1l/JnUWNLrvGTzHFaiiUvOWgzg3Df/R8WNkkQT +MvDkrhkDO7FSvtmVZ7NvYJNALhZdBdpIIXlSFCUzGdNYEjUVwphjI9AFqKC3x2T zifk4TfQ4zkd1RFdvqvoj0S24RBPC8BYPGeAsUb4Sys77Qh2Qb5Vl4mi3tUFUNNy IMox/yewQwTtKVfIpZW0fMfxZwquSu9aV798xIAKYZwilEdZtEncbA7KWjEiZzx7 Q4b/NKAJZseHw10GcYULM4Q1k+ZIQC1zayPRsh1HqAmGRP9GUd3H95DMliFaRl1G bR54OwZbbaJBQ9XTTS1yIxK4OK1fxeo28ZqZdMCsbVmSMKi9amCqTon4X+0/+pUZ nWh0bewWigMLnOr5xLdCAp6/QA9AC4IsW5tu0oTMO82jgqSNQiVsdtu4FYdgjZxm lW81CXMW0SUdISTf9rCRex4J/7xqVT/cbcZrbG7dzFKzjp1EyzlfiWbRo+Sl8z5X +75yF5b3L86qG21c8/7vO56WVt+bMJz2vc8eoT9nZaEagUw/mXZeXCYbuAfd31G5 WjHYgnP7DwhNKmxAASoBcBjyWNeMz0nxzPUQl0HEWbHFR+S9RX+mzQVk0JZwyXme K4ZvI8Lbha0=PL2r -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for file is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: file security update Advisory ID: RHSA-2020:2521-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:2521 Issue date: 2020-06-10 CVE Names: CVE-2018-10360 ==================================================================== 1. Summary: An update for file is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode EUS (v. 7.7) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7) - x86_64 Red Hat Enterprise Linux Server EUS (v. 7.7) - noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional EUS (v. 7.7) - ppc64, ppc64le, s390x, x86_64 3. Description: The file command is used to identify a particular file according to the type of data the file contains. It can identify many different file types, including Executable and Linkable Format (ELF) binary files, system libraries, RPM packages, and different graphics formats. Security Fix(es): * file: out-of-bounds read via a crafted ELF file (CVE-2018-10360) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details onhow to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1590000 - CVE-2018-10360 file: out-of-bounds read via a crafted ELF file 6. Package List: Red Hat Enterprise Linux ComputeNode EUS (v. 7.7): Source: file-5.11-35.el7_7.1.src.rpm noarch: python-magic-5.11-35.el7_7.1.noarch.rpm x86_64: file-5.11-35.el7_7.1.x86_64.rpm file-debuginfo-5.11-35.el7_7.1.i686.rpm file-debuginfo-5.11-35.el7_7.1.x86_64.rpm file-libs-5.11-35.el7_7.1.i686.rpm file-libs-5.11-35.el7_7.1.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7): x86_64: file-debuginfo-5.11-35.el7_7.1.i686.rpm file-debuginfo-5.11-35.el7_7.1.x86_64.rpm file-devel-5.11-35.el7_7.1.i686.rpm file-devel-5.11-35.el7_7.1.x86_64.rpm file-static-5.11-35.el7_7.1.i686.rpm file-static-5.11-35.el7_7.1.x86_64.rpm Red Hat Enterprise Linux Server EUS (v. 7.7): Source: file-5.11-35.el7_7.1.src.rpm noarch: python-magic-5.11-35.el7_7.1.noarch.rpm ppc64: file-5.11-35.el7_7.1.ppc64.rpm file-debuginfo-5.11-35.el7_7.1.ppc.rpm file-debuginfo-5.11-35.el7_7.1.ppc64.rpm file-libs-5.11-35.el7_7.1.ppc.rpm file-libs-5.11-35.el7_7.1.ppc64.rpm ppc64le: file-5.11-35.el7_7.1.ppc64le.rpm file-debuginfo-5.11-35.el7_7.1.ppc64le.rpm file-libs-5.11-35.el7_7.1.ppc64le.rpm s390x: file-5.11-35.el7_7.1.s390x.rpm file-debuginfo-5.11-35.el7_7.1.s390.rpm file-debuginfo-5.11-35.el7_7.1.s390x.rpm file-libs-5.11-35.el7_7.1.s390.rpm file-libs-5.11-35.el7_7.1.s390x.rpm x86_64: file-5.11-35.el7_7.1.x86_64.rpm file-debuginfo-5.11-35.el7_7.1.i686.rpm file-debuginfo-5.11-35.el7_7.1.x86_64.rpm file-libs-5.11-35.el7_7.1.i686.rpm file-libs-5.11-35.el7_7.1.x86_64.rpm Red Hat Enterprise Linux Server Optional EUS (v.7.7): ppc64: file-debuginfo-5.11-35.el7_7.1.ppc.rpm file-debuginfo-5.11-35.el7_7.1.ppc64.rpm file-devel-5.11-35.el7_7.1.ppc.rpm file-devel-5.11-35.el7_7.1.ppc64.rpm file-static-5.11-35.el7_7.1.ppc.rpm file-static-5.11-35.el7_7.1.ppc64.rpm ppc64le: file-debuginfo-5.11-35.el7_7.1.ppc64le.rpm file-devel-5.11-35.el7_7.1.ppc64le.rpm file-static-5.11-35.el7_7.1.ppc64le.rpm s390x: file-debuginfo-5.11-35.el7_7.1.s390.rpm file-debuginfo-5.11-35.el7_7.1.s390x.rpm file-devel-5.11-35.el7_7.1.s390.rpm file-devel-5.11-35.el7_7.1.s390x.rpm file-static-5.11-35.el7_7.1.s390.rpm file-static-5.11-35.el7_7.1.s390x.rpm x86_64: file-debuginfo-5.11-35.el7_7.1.i686.rpm file-debuginfo-5.11-35.el7_7.1.x86_64.rpm file-devel-5.11-35.el7_7.1.i686.rpm file-devel-5.11-35.el7_7.1.x86_64.rpm file-static-5.11-35.el7_7.1.i686.rpm file-static-5.11-35.el7_7.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2018-10360 https://access.redhat.com/security/updates/classification/#low 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXuGSvNzjgjWX9erEAQhYuxAAgCApcTSpqx1TKRg0zcaIpHRvS6flHDez sO+aT2irDyRjuuquYtwKUkZlxeej976buAgd45GExizYKlT9Jpk+jftdZu6yd7Yb eI1I1dJVTLFI+NprMJgVaVEoKsAkh0iiVv9fzsYhmuHmWSk+ATiRZpZCK9Ljl1fg FC2omGVMLqt4a0UhQ9/ZZhc0Dj7UvwVnU7UBd5njfAPKuvjljM1H4HtoHUuwM99i qa5XvIbRPpnlUafJ2VK3xedDSYB97qmcN/n0ntS4zoJp+sQ1PBwOxj18d3d1Bqda Euym2uBBvEIkxMbI3cuyidSNpeZxSS2lDcPoNhJQgrjZJeha1WwQ68f1I2yFNb44 dDHp7Pb/a2idXrtsB8BAEDoBb9ggF9Rk0Gb2q788dqiQ8BonNrxoOUIyAvDSecsu gB8HwDjpxxJYQEb8MIca8JgSco22X8s/jSzhBkUWvMp0OIIl916z2Oxp6we+Kg1c eKs2qWRU3FDAJ8UOaNMtE0dgHrh8i+r/DFs03KTAbxSXszm6cp+VISCr7fzvoDlw 6JHG0FMhrPNJ8TOE7ZSoxk5SpWUeGYNauoxFVEzMyS2QdNjeKv61mm0SbZFmjoUW FeE/FdXlPZd+AsD5vPWlsOtx61Q5Gi/PlBnM8hR58fNxvsCPsWDrf4eAObb5DCGE +8I2kjew1cE=+mwk -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update that solves one vulnerability and has one errata is now available.. openSUSE Security Update: Security update for file ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0677-1 Rating: moderate References: #1154661 #1169512 Cross-References: CVE-2019-18218 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for file fixes the following issues: Security issues fixed: - CVE-2019-18218: Fixed a heap-based buffer overflow in cdf_read_property_info() (bsc#1154661). Non-security issue fixed: - Fixed broken '--help' output (bsc#1169512). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-677=1 Package List: - openSUSE Leap 15.1 (i586 x86_64): file-5.32-lp151.8.3.1 file-debuginfo-5.32-lp151.8.3.1 file-debugsource-5.32-lp151.8.3.1 file-devel-5.32-lp151.8.3.1 libmagic1-5.32-lp151.8.3.1 libmagic1-debuginfo-5.32-lp151.8.3.1 python2-magic-5.32-lp151.8.3.1 python3-magic-5.32-lp151.8.3.1 - openSUSE Leap 15.1 (x86_64): file-devel-32bit-5.32-lp151.8.3.1 libmagic1-32bit-5.32-lp151.8.3.1 libmagic1-32bit-debuginfo-5.32-lp151.8.3.1 - openSUSE Leap 15.1 (noarch): file-magic-5.32-lp151.8.3.1 References: https://www.suse.com/security/cve/CVE-2019-18218.html https://bugzilla.suse.com/1154661 https://bugzilla.suse.com/1169512 -- . The Fedora patch tackles a significant memory leak in network services,enhancing both protection and performance.. openSUSE Update, Buffer Overflow Fix, Software Security Patch. . LinuxSecurity.com Team
New file packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] file (SSA:2019-054-01) New file packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. Here are the details from the Slackware 14.2 ChangeLog: +--------------------------+ patches/packages/file-5.36-i586-1_slack14.2.txz: Upgraded. Fix out-of-bounds read and denial-of-service security issues: For more information, see: https://www.cve.org/CVERecord?id=CVE-2019-8906 https://www.cve.org/CVERecord?id=CVE-2019-8907 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 14.0: ftp://ftp.slackware.com/pub/slackware/slackware-14.0/patches/packages/file-5.36-i486-1_slack14.0.txz Updated package for Slackware x86_64 14.0: ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/packages/file-5.36-x86_64-1_slack14.0.txz Updated package for Slackware 14.1: ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/file-5.36-i486-1_slack14.1.txz Updated package for Slackware x86_64 14.1: ftp://ftp.slackware.com/pub/slackware/slackware64-14.1/patches/packages/file-5.36-x86_64-1_slack14.1.txz Updated package for Slackware 14.2: ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/file-5.36-i586-1_slack14.2.txz Updated package for Slackware x86_64 14.2: ftp://ftp.slackware.com/pub/slackware/slackware64-14.2/patches/packages/file-5.36-x86_64-1_slack14.2.txz Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 14.0 package: d774a800d99acb0ad52f312ed83a072f file-5.36-i486-1_slack14.0.txz Slackware x86_64 14.0 package: 7be0a75f9f31f23b9c38b7ebf0192961 file-5.36-x86_64-1_slack14.0.txz Slackware 14.1 package: 0ec7575d2786bb8c8abe7b568cab262f file-5.36-i486-1_slack14.1.txz Slackware x86_64 14.1 package: ca23033d9beedda72c0793b796ad10b2 file-5.36-x86_64-1_slack14.1.txz Slackware 14.2 package: 4dfa9268d6415052d99681543a884227 file-5.36-i586-1_slack14.2.txz Slackware x86_64 14.2 package: 2e26d570e7b3c957155905b9150b1af0 file-5.36-x86_64-1_slack14.2.txz Slackware -current package: 039ec7588178a2026e77bd96d2c98552 a/file-5.36-i586-1.txz Slackware x86_64 -current package: 20d07d173c3a2314eabe27620f662195 a/file-5.36-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg file-5.36-i586-1_slack14.2.txz +-----+ . Updated package files have been released for Slackware distributions to address security vulnerabilities, particularly concerning DoS risks.. Slackware Security Update, File Package Fix, DoS Threat, Security Advisories. . LinuxSecurity.com Team
Moderate: file security and bug fix update. Date: Mon, 21 Dec 2015 23:13:34 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Moderate: file on SL7.x x86_64 MIME-Version: 1.0 Message-ID: Synopsis: Moderate: file security and bug fix update Advisory ID: SLSA-2015:2155-7 Issue Date: 2015-11-19 CVE Numbers: CVE-2014-0238 CVE-2014-0237 CVE-2014-3480 CVE-2014-3479 CVE-2014-0207 CVE-2014-3487 CVE-2014-3587 CVE-2014-3538 CVE-2014-3478 CVE-2014-3710 CVE-2014-9652 CVE-2014-8116 CVE-2014-8117 CVE-2014-9653 -- Multiple denial of service flaws were found in the way file parsed certain Composite Document Format (CDF) files. A remote attacker could use either of these flaws to crash file, or an application using file, via a specially crafted CDF file. (CVE-2014-0207, CVE-2014-0237, CVE-2014-0238, CVE-2014-3479, CVE-2014-3480, CVE-2014-3487, CVE-2014-3587) Two flaws were found in the way file processed certain Pascal strings. A remote attacker could cause file to crash if it was used to identify the type of the attacker-supplied file. (CVE-2014-3478, CVE-2014-9652) Multiple flaws were found in the file regular expression rules for detecting various files. A remote attacker could use these flaws to cause file to consume an excessive amount of CPU. (CVE-2014-3538) Multiple flaws were found in the way file parsed Executable and Linkable Format (ELF) files. A remote attacker could use these flaws to cause file to crash, disclose portions of its memory, or consume an excessive amount of system resources. (CVE-2014-3710, CVE-2014-8116, CVE-2014-8117, CVE-2014-9653) The file packages have been updated to ensure correct operation on Power little endian and ARM 64-bit hardware architectures. -- SL7 x86_64 file-5.11-31.el7.x86_64.rpm file-debuginfo-5.11-31.el7.i686.rpm file-debuginfo-5.11-31.el7.x86_64.rpm file-libs-5.11-31.el7.i686.rpm file-libs-5.11-31.el7.x86_64.rpm file-devel-5.11-31.el7.i686.rpm file-devel-5.11-31.el7.x86_64.rpm file-static-5.11-31.el7.i686.rpm file-static-5.11-31.el7.x86_64.rpm noarch python-magic-5.11-31.el7.noarch.rpm - Scientific Linux Development Team . Patches for Scientific Linux address numerous vulnerabilities that caused service interruptions, promoting reliable operation.. Security Patch, Scientific Linux, Denial of Service, Moderate Fix. . Severity: Important. LinuxSecurity.com Team
Updated file packages that fix multiple security issues and several bugs are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having Moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: file security and bug fix update Advisory ID: RHSA-2015:2155-07 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2015:2155.html Issue date: 2015-11-19 CVE Names: CVE-2014-0207 CVE-2014-0237 CVE-2014-0238 CVE-2014-3478 CVE-2014-3479 CVE-2014-3480 CVE-2014-3487 CVE-2014-3538 CVE-2014-3587 CVE-2014-3710 CVE-2014-8116 CVE-2014-8117 CVE-2014-9652 CVE-2014-9653 ==================================================================== 1. Summary: Updated file packages that fix multiple security issues and several bugs are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having Moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server (v. 7) - aarch64, noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - aarch64, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 3. Description: The filecommand is used to identify a particular file according to the type of data the file contains. It can identify many different file types, including Executable and Linkable Format (ELF) binary files, system libraries, RPM packages, and different graphics formats. Multiple denial of service flaws were found in the way file parsed certain Composite Document Format (CDF) files. A remote attacker could use either of these flaws to crash file, or an application using file, via a specially crafted CDF file. (CVE-2014-0207, CVE-2014-0237, CVE-2014-0238, CVE-2014-3479, CVE-2014-3480, CVE-2014-3487, CVE-2014-3587) Two flaws were found in the way file processed certain Pascal strings. A remote attacker could cause file to crash if it was used to identify the type of the attacker-supplied file. (CVE-2014-3478, CVE-2014-9652) Multiple flaws were found in the file regular expression rules for detecting various files. A remote attacker could use these flaws to cause file to consume an excessive amount of CPU. (CVE-2014-3538) Multiple flaws were found in the way file parsed Executable and Linkable Format (ELF) files. A remote attacker could use these flaws to cause file to crash, disclose portions of its memory, or consume an excessive amount of system resources. (CVE-2014-3710, CVE-2014-8116, CVE-2014-8117, CVE-2014-9653) Red Hat would like to thank Thomas Jarosch of Intra2net AG for reporting the CVE-2014-8116 and CVE-2014-8117 issues. The CVE-2014-0207, CVE-2014-0237, CVE-2014-0238, CVE-2014-3478, CVE-2014-3479, CVE-2014-3480, CVE-2014-3487, CVE-2014-3710 issues were discovered by Francisco Alonso of Red Hat Product Security; the CVE-2014-3538 issue was discovered by Jan Kaluža of the Red Hat Web Stack Team The file packages have been updated to ensure correct operation on Power little endian and ARM 64-bit hardware architectures. (BZ#1224667, BZ#1224668, BZ#1157850, BZ#1067688). All file users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. 4.Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1064167 - back out patch to MAXDESC 1091842 - CVE-2014-0207 file: cdf_read_short_sector insufficient boundary check 1094648 - file reports JPEG image as 'Minix filesystem' 1098155 - CVE-2014-0238 file: CDF property info parsing nelements infinite loop 1098193 - CVE-2014-0237 file: cdf_unpack_summary_info() excessive looping DoS 1098222 - CVE-2014-3538 file: unrestricted regular expression matching 1104858 - CVE-2014-3480 file: cdf_count_chain insufficient boundary check 1104863 - CVE-2014-3478 file: mconvert incorrect handling of truncated pascal string size 1104869 - CVE-2014-3479 file: cdf_check_stream_offset insufficient boundary check 1107544 - CVE-2014-3487 file: cdf_read_property_info insufficient boundary check 1128587 - CVE-2014-3587 file: incomplete fix for CVE-2012-1571 in cdf_read_property_info 1155071 - CVE-2014-3710 file: out-of-bounds read in elf note headers1157850 - File command does not recognize kernel images on ppc64le 1161911 - file command does not display "from" field correctly when run on 32 bit ppc core file 1161912 - too many spaces ... 1171580 - CVE-2014-8116 file: multiple denial of service issues (resource consumption) 1174606 - CVE-2014-8117 file: denial of service issue (resource consumption) 1188599 - CVE-2014-9652 file: out of bounds read in mconvert() 1190116 - CVE-2014-9653 file: malformed elf file causes access to uninitialized memory 1224667 - aarch64: "file" fails to get the whole information of the new swap partition 1224668 - ppc64le: "file" fails to get the whole information of the new swap partition 1255396 - BuildID[sha1] sum is architecture dependent 6. Package List: Red Hat Enterprise Linux Client (v.7): Source: file-5.11-31.el7.src.rpm noarch: python-magic-5.11-31.el7.noarch.rpm x86_64: file-5.11-31.el7.x86_64.rpm file-debuginfo-5.11-31.el7.i686.rpm file-debuginfo-5.11-31.el7.x86_64.rpm file-libs-5.11-31.el7.i686.rpm file-libs-5.11-31.el7.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): x86_64: file-debuginfo-5.11-31.el7.i686.rpm file-debuginfo-5.11-31.el7.x86_64.rpm file-devel-5.11-31.el7.i686.rpm file-devel-5.11-31.el7.x86_64.rpm file-static-5.11-31.el7.i686.rpm file-static-5.11-31.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v. 7): Source: file-5.11-31.el7.src.rpm noarch: python-magic-5.11-31.el7.noarch.rpm x86_64: file-5.11-31.el7.x86_64.rpm file-debuginfo-5.11-31.el7.i686.rpm file-debuginfo-5.11-31.el7.x86_64.rpm file-libs-5.11-31.el7.i686.rpm file-libs-5.11-31.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): x86_64: file-debuginfo-5.11-31.el7.i686.rpm file-debuginfo-5.11-31.el7.x86_64.rpm file-devel-5.11-31.el7.i686.rpm file-devel-5.11-31.el7.x86_64.rpm file-static-5.11-31.el7.i686.rpm file-static-5.11-31.el7.x86_64.rpm Red Hat Enterprise Linux Server (v. 7): Source: file-5.11-31.el7.src.rpm aarch64: file-5.11-31.el7.aarch64.rpm file-debuginfo-5.11-31.el7.aarch64.rpm file-libs-5.11-31.el7.aarch64.rpm noarch: python-magic-5.11-31.el7.noarch.rpm ppc64: file-5.11-31.el7.ppc64.rpm file-debuginfo-5.11-31.el7.ppc.rpm file-debuginfo-5.11-31.el7.ppc64.rpm file-libs-5.11-31.el7.ppc.rpm file-libs-5.11-31.el7.ppc64.rpm ppc64le: file-5.11-31.el7.ppc64le.rpm file-debuginfo-5.11-31.el7.ppc64le.rpm file-libs-5.11-31.el7.ppc64le.rpm s390x: file-5.11-31.el7.s390x.rpm file-debuginfo-5.11-31.el7.s390.rpm file-debuginfo-5.11-31.el7.s390x.rpm file-libs-5.11-31.el7.s390.rpm file-libs-5.11-31.el7.s390x.rpm x86_64: file-5.11-31.el7.x86_64.rpm file-debuginfo-5.11-31.el7.i686.rpm file-debuginfo-5.11-31.el7.x86_64.rpm file-libs-5.11-31.el7.i686.rpm file-libs-5.11-31.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.7): aarch64: file-debuginfo-5.11-31.el7.aarch64.rpm file-devel-5.11-31.el7.aarch64.rpm file-static-5.11-31.el7.aarch64.rpm ppc64: file-debuginfo-5.11-31.el7.ppc.rpm file-debuginfo-5.11-31.el7.ppc64.rpm file-devel-5.11-31.el7.ppc.rpm file-devel-5.11-31.el7.ppc64.rpm file-static-5.11-31.el7.ppc.rpm file-static-5.11-31.el7.ppc64.rpm ppc64le: file-debuginfo-5.11-31.el7.ppc64le.rpm file-devel-5.11-31.el7.ppc64le.rpm file-static-5.11-31.el7.ppc64le.rpm s390x: file-debuginfo-5.11-31.el7.s390.rpm file-debuginfo-5.11-31.el7.s390x.rpm file-devel-5.11-31.el7.s390.rpm file-devel-5.11-31.el7.s390x.rpm file-static-5.11-31.el7.s390.rpm file-static-5.11-31.el7.s390x.rpm x86_64: file-debuginfo-5.11-31.el7.i686.rpm file-debuginfo-5.11-31.el7.x86_64.rpm file-devel-5.11-31.el7.i686.rpm file-devel-5.11-31.el7.x86_64.rpm file-static-5.11-31.el7.i686.rpm file-static-5.11-31.el7.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: file-5.11-31.el7.src.rpm noarch: python-magic-5.11-31.el7.noarch.rpm x86_64: file-5.11-31.el7.x86_64.rpm file-debuginfo-5.11-31.el7.i686.rpm file-debuginfo-5.11-31.el7.x86_64.rpm file-libs-5.11-31.el7.i686.rpm file-libs-5.11-31.el7.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): x86_64: file-debuginfo-5.11-31.el7.i686.rpm file-debuginfo-5.11-31.el7.x86_64.rpm file-devel-5.11-31.el7.i686.rpm file-devel-5.11-31.el7.x86_64.rpm file-static-5.11-31.el7.i686.rpm file-static-5.11-31.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2014-0207 https://access.redhat.com/security/cve/CVE-2014-0237 https://access.redhat.com/security/cve/CVE-2014-0238 https://access.redhat.com/security/cve/CVE-2014-3478 https://access.redhat.com/security/cve/CVE-2014-3479 https://access.redhat.com/security/cve/CVE-2014-3480 https://access.redhat.com/security/cve/CVE-2014-3487 https://access.redhat.com/security/cve/CVE-2014-3538 https://access.redhat.com/security/cve/CVE-2014-3587 https://access.redhat.com/security/cve/CVE-2014-3710 https://access.redhat.com/security/cve/CVE-2014-8116 https://access.redhat.com/security/cve/CVE-2014-8117 https://access.redhat.com/security/cve/CVE-2014-9652 https://access.redhat.com/security/cve/CVE-2014-9653 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFWTkCyXlSAg2UNWIIRAupSAJ0TVUyMQqn/7m4ByA2ijXC3gaC3YwCfR9jS qi8oKX7gvmn7L6fqQ5qhg/0=oh/6 -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Get the latest Linux and open source security news straight to your inbox.