CVE-2014-2270 is a denial-of-service vulnerability affecting the 'file' utility (before version 5.17) and libmagic, impacting products like Canonical, Debian, openSUSE, and PHP. An attacker can trigger an out-of-bounds memory access and crash by providing a crafted PE executable with malicious offsets in its softmagic. This vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and partial availability impact, but no active exploits, public exploit code, or significant community discussion have been observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.17CPE matchmatch criteria | cpe:2.3:a:file_project:file:*:*:*:*:*:*:*:* | ||
< 5.4.26CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
>= 5.5.0, < 5.5.10CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.