CVE Vulnerabilities

CVE-2014-1943

Improper Handling of Exceptional Conditions

Published: Feb 18, 2014 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted indirect offset value in the magic of a file.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

NameVendorStart VersionEnd Version
Fine_free_fileFine_free_file_project*5.17 (excluding)
Red Hat Enterprise Linux 5RedHatphp53-0:5.3.3-23.el5_10*
Red Hat Enterprise Linux 6RedHatphp-0:5.3.3-27.el6_5.1*
Red Hat Enterprise Linux 6RedHatfile-0:5.04-21.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6RedHatphp54-php-0:5.4.16-22.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUSRedHatphp54-php-0:5.4.16-22.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.5 EUSRedHatphp54-php-0:5.4.16-22.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.6 EUSRedHatphp54-php-0:5.4.16-22.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 7RedHatphp54-php-0:5.4.16-22.el7*
FileUbuntudevel*
FileUbuntulucid*
FileUbuntuprecise*
FileUbuntuquantal*
FileUbuntusaucy*
FileUbuntuupstream*
Php5Ubuntudevel*
Php5Ubuntulucid*
Php5Ubuntuprecise*
Php5Ubuntuquantal*
Php5Ubuntusaucy*
Php5Ubuntuupstream*

References