drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mehrere Probleme in file
Name: |
Mehrere Probleme in file |
|
ID: |
USN-2494-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 10.04 LTS, Ubuntu 12.04 LTS, Ubuntu 14.04 LTS, Ubuntu 14.10 |
|
Datum: |
Mi, 4. Februar 2015, 21:30 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3710
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8116
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8117 |
|
Applikationen: |
file |
|
Originalnachricht |
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============4012723027736621570== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="Jxgxd0m5bkUdhA0XnIjCavF5ClpIjeHES"
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --Jxgxd0m5bkUdhA0XnIjCavF5ClpIjeHES Content-Type: text/plain; charset=utf- Content-Transfer-Encoding: quoted-printable
========================================================================== Ubuntu Security Notice USN-2494-1 February 04, 2015
file vulnerabilities ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS - Ubuntu 10.04 LTS
Summary:
file could be made to crash if it opened a specially crafted file.
Software Description: - file: Tool to determine file types
Details:
Francisco Alonso discovered that file incorrectly handled certain ELF files. An attacker could use this issue to cause file to crash, resulting in a denial of service. (CVE-2014-3710)
Thomas Jarosch discovered that file incorrectly handled certain ELF files. An attacker could use this issue to cause file to hang or crash, resulting in a denial of service. (CVE-2014-8116)
Thomas Jarosch discovered that file incorrectly limited recursion. An attacker could use this issue to cause file to hang or crash, resulting in a denial of service. (CVE-2014-8117)
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 14.10: file 1:5.19-1ubuntu1.2
Ubuntu 14.04 LTS: file 1:5.14-2ubuntu3.3
Ubuntu 12.04 LTS: file 5.09-2ubuntu0.6
Ubuntu 10.04 LTS: file 5.03-5ubuntu1.5
In general, a standard system update will make all the necessary changes.
References: http://www.ubuntu.com/usn/usn-2494-1 CVE-2014-3710, CVE-2014-8116, CVE-2014-8117
Package Information: https://launchpad.net/ubuntu/+source/file/1:5.19-1ubuntu1.2 https://launchpad.net/ubuntu/+source/file/1:5.14-2ubuntu3.3 https://launchpad.net/ubuntu/+source/file/5.09-2ubuntu0.6 https://launchpad.net/ubuntu/+source/file/5.03-5ubuntu1.5
--Jxgxd0m5bkUdhA0XnIjCavF5ClpIjeHES Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc"
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1
iQIcBAEBCgAGBQJU0m0NAAoJEGVp2FWnRL6TyjkP/iOkgItRxbEKvv7eqVfEpLX5 q/BaW75AKk2OLw7ia1LW/7sovZrSAkIqg9sDJwdayigkcKUqTUQXPqp/t/DHD1sv Y5QEJuZVeLNJmilmdZyrAwb8JIkyWnIiWV93STUfULcuUiBjo9v/7ZR3O96uYKt+ edech7970LcIllYcXN2sg5GIRR3oUTG0qdttIaQoJGcmvkpX2Nq8OVP93S+mzZts JYSZiAe2Hcnu71RZ3BzvyRM4H6s9Z9YOm9u7GxFWK5Kv6HniIWLCYoTSO5VwwAjL wWUXNKH1UEvTYmF4s4KjVQH+lZW2QTfhgk9bz2jV7r6krlK8/K20/Y8oyllQrDaN SRNghCSBNzyHjejTEGytAGKYHM/NBiJXHMzJ1os9z7YpczTZ1uITeX1RVgOVFzVg 7Lvvopxbma0l8cUViwbk370WFGALSglG+5iPt/+v+4pOXVX7Zf5RHz1mr3L0ngls wzljNr4zN2jVid8iuPwlEqJ3bpzzKBkI/bH5BMugtXmjdFjm5ukyQRANMk2QKgqw mqXcI3mGaxI5AEPw/zW3TFY/2XT4mPBwQFXHT6rWwhg7kyglfj/EP0nbI7NJBa8U QkSkxkNaMNJpYOkc/0QeR+/2GFzysClp7dyn11CXYVyIf25dgc9cDtj0NoBgxl4a Zeb5YI8k/eGwDE+TzXCN =CaP9 -----END PGP SIGNATURE-----
--Jxgxd0m5bkUdhA0XnIjCavF5ClpIjeHES--
--===============4012723027736621570== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline
-- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
--===============4012723027736621570==--
|
|
|
|