Bug 1098209 (CVE-2014-0236) - CVE-2014-0236 file: root_storage NULL pointer deference flaw in CDF parser
Summary: CVE-2014-0236 file: root_storage NULL pointer deference flaw in CDF parser
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2014-0236
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 1065838
TreeView+ depends on / blocked
 
Reported: 2014-05-15 13:30 UTC by Francisco Alonso
Modified: 2023-05-12 13:15 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2014-06-30 10:57:35 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
PHP Bug Tracker 67329 0 None None None Never

Description Francisco Alonso 2014-05-15 13:30:50 UTC
NULL pointer deference flaw was found in the way file processed root_storage entries in Composite Document Files (CDF).  A crafted CDF file could cause file to crash.

This issue was introduced in the following commit:
https://github.com/file/file/commit/209113ac443c82cc7573bb228b68ce1dd9d50f90

This change was introduced in upstream version 5.18, previous versions are not affected.

Comment 1 Francisco Alonso 2014-05-22 13:17:07 UTC
Acknowledgment:

This issue was discovered by Francisco Alonso of the Red Hat Security Response Team.

Comment 2 Remi Collet 2014-05-22 14:33:05 UTC
PHP bug https://bugs.php.net/bug.php?id=67329

Comment 3 Tomas Hoger 2014-05-26 08:58:51 UTC
Upstream fix (src/readcdf.c part of this upstream commit):
https://github.com/file/file/commit/6d209c1c489457397a5763bca4b28e43aac90391#diff-1

Comment 4 Tomas Hoger 2014-05-26 09:00:40 UTC
The versions of file in current Red Hat Enterprise Linux and Fedora versions, as well as versions of file included in the php packages in current Red Hat Enterprise Linux and Fedora versions, are older than 5.18 and hence are not affected by this issue.

Statement:

Not vulnerable. This issue did not affect the versions of file, php, and php53 as shipped with Red Hat Enterprise Linux 5 and 6.


Note You need to log in before you can comment on or make changes to this bug.