← All CVEs

CVE-2014-3538

medium · 5

file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7345.

5
CVSS
11.8%
EPSS (exploit prob.)
96th
EPSS percentile
2014-07-03
Published

AV:N/AC:L/Au:N/C:N/I:N/A:P

Weaknesses

CWE-399

Affected products

VendorProductAffected versions
christos_zoulasfile<= 5.18
christos_zoulasfile5.00
christos_zoulasfile5.01
christos_zoulasfile5.02
christos_zoulasfile5.03
christos_zoulasfile5.04
christos_zoulasfile5.05
christos_zoulasfile5.06
christos_zoulasfile5.07
christos_zoulasfile5.08
christos_zoulasfile5.09
christos_zoulasfile5.10
christos_zoulasfile5.11
christos_zoulasfile5.12
christos_zoulasfile5.13
christos_zoulasfile5.14
christos_zoulasfile5.15
christos_zoulasfile5.16
christos_zoulasfile5.17
phpphp>= 5.4.0, < 5.4.32
phpphp>= 5.5.0, < 5.5.16
debiandebian_linux7.0
debiandebian_linux8.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-3538