CVE-2014-1943 describes a denial-of-service vulnerability in Fine Free file versions prior to 5.17, affecting products like Canonical, Debian, and PHP. An unauthenticated attacker can exploit this by providing a specially crafted file with an indirect offset value in its magic, leading to infinite recursion, high CPU consumption, and a system crash. With a CVSS score of 5.0 and no known public exploits, the vulnerability is not actively exploited, lacks readily available exploit code, and has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.17CPE matchmatch criteria | cpe:2.3:a:fine_free_file_project:fine_free_file:*:*:*:*:*:*:*:* | ||
>= 5.4.0, < 5.4.26CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
>= 5.5.0, < 5.5.10CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
10.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.