• [SECURITY] [DSA 3072-1] file security update

    From Thijs Kinkhorst@1:229/2 to All on Wed Nov 12 10:30:03 2014
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-3072-1 [email protected] http://www.debian.org/security/ Thijs Kinkhorst November 11, 2014 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : file
    CVE ID : CVE-2014-3710
    Debian Bug : 768806

    Francisco Alonso of Red Hat Product Security found an issue in the file utility: when checking ELF files, note headers are incorrectly checked,
    thus potentially allowing attackers to cause a denial of service
    (out-of-bounds read and application crash) by supplying a specially
    crafted ELF file.

    For the stable distribution (wheezy), this problem has been fixed in
    version 5.11-2+deb7u6.

    For the upcoming stable distribution (jessie), this problem will be
    fixed soon.

    For the unstable distribution (sid), this problem has been fixed in
    version 1:5.20-2.

    We recommend that you upgrade your file packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1

    iQEcBAEBAgAGBQJUYm9mAAoJEFb2GnlAHawEXA4H/RrutSaDAEKKDlYI/r53xP2J QVoS9h4sagxs9NMfkVjUK5mAvHp+kqWvMEXOjBeauucenmgDU4A48BnwtqSAzHJG WWdG6UPzoMqWL7SzG61ejjn3KOUNFctYhIR+QGfxw2WXxMJ7S6KGKdS/Gz6Ewz8E e7C2E20DbLgO7Ky8KrgHAWJLUkYBydTn6WyluXDPkBFXWOPZJ9fX1SBZoeNFLMey aMzbdF/VQPeV5YEiuJIlXkqiHHUfwpFqgkGaJfKQZRU+VxFez22Vd4k1RUN7I9ey RoRIvF/hKaovhEnnBVme227LxLGhK/EHHTwhp0qfE02R8YTPn+6+fi20fv+zWBQ=
    =wqAt
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: https://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)