The gnu regular expression code in file 4.20 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted document with a large number of line feed characters, which is not well handled by OS/2 REXX regular expressions that use wildcards, as originally reported for AMaViS.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Virus_scanner | Amavis | * | * |
File | Gentoo | 4.20 (including) | 4.20 (including) |
File | Ubuntu | devel | * |