Debian Security Advisory
DSA-2422-2 file -- missing bounds checks
- Date Reported:
- 09 May 2012
- Affected Packages:
- file
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2012-1571.
- More information:
-
The file type identification tool, file, and its associated library, libmagic, do not properly process malformed files in the Composite Document File (CDF) format, leading to crashes.
Note that after this update, file may return different detection results for CDF files (well-formed or not). The new detections are believed to be more accurate.
For the stable distribution (squeeze), this problem has been fixed in version 5.04-5+squeeze2.
We recommend that you upgrade your file packages.