[Full-disclosure] FLEA-2007-0022-1: file



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Foresight Linux Essential Advisory: 2007-0022-1
Published: 2007-05-24

Rating: Moderate

Updated Versions:
file=/conary.rpath.com@rpl:devel//1/4.21-1-0.1
group-dist=/foresight.rpath.org at fl:1-devel//1/1.2.2-0.10-3

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2026
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2799
https://issues.rpath.com/browse/RPL-1311

Description:
Previous versions of the file package are vulnerable to two attacks in which
a maliciously crafted file can cause the file command, and any other application
using libmagic, to use excessive CPU resources (Denial of Service), crash, or
execute arbitrary, attacker-provided code.

- ---

Copyright 2007 Foresight Linux Project
Portions Copyright 2007 rPath, Inc.
This file is distributed under the terms of the MIT License.
A copy is available at http://www.foresightlinux.org/permanent/mit-license.html

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.4 (GNU/Linux)

iD8DBQFGVfoZ0e1Yawpq2XMRAvZUAJ9o/n19UrGm71OgKZfqhbmEIJNrmgCfWap6
PSafFmhDzk2N2hy0koB7fgQ=
=ivEn
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • [Full-disclosure] FLEA-2007-0034-1:
    ... Previous versions of the lighttpd package are vulnerable to multiple ... attacks, among which remote attackers may circumvent access-control ... It has not been determined that these vulnerabilities can ... Copyright 2007 Foresight Linux Project ...
    (Full-Disclosure)
  • FLEA-2007-0034-1:
    ... Previous versions of the lighttpd package are vulnerable to multiple ... attacks, among which remote attackers may circumvent access-control ... It has not been determined that these vulnerabilities can ... Copyright 2007 Foresight Linux Project ...
    (Bugtraq)
  • FLEA-2007-0022-1: file
    ... Previous versions of the file package are vulnerable to two attacks in which ... Copyright 2007 Foresight Linux Project ... Portions Copyright 2007 rPath, Inc. ...
    (Bugtraq)
  • [Full-disclosure] FLEA-2007-0052-1 gd
    ... Previous versions of the gd package are vulnerable to multiple attacks in ... the gd library to load existing images rather than generate new images. ... Copyright 2007 Foresight Linux Project ... Portions copyright 2007 rPath Inc. ...
    (Full-Disclosure)
  • Re: Damn you, FEDEX! or Nikon D40 lost in Springfield, MO blackhole.
    ... the 2 mp Mavica he had been using with a Nikon D40. ... After shopping around, he got me to order one for him. ... The shipper had it insured, but from what I have read it could take weeks to sort this crap out. ... You may get your insurance from FedEx and a couple weeks later they find it and deliver it. ...
    (alt.photography)