Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1180642 - (CVE-2014-9621) CVE-2014-9621 file: limit string printing to 100 chars
CVE-2014-9621 file: limit string printing to 100 chars
Status: CLOSED NOTABUG
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
impact=low,public=20150103,reported=2...
: Security
: 1175083 (view as bug list)
Depends On: 1180643
Blocks: 1180646
  Show dependency treegraph
 
Reported: 2015-01-09 10:48 EST by Vasyl Kaigorodov
Modified: 2015-11-27 06:48 EST (History)
9 users (show)

See Also:
Fixed In Version: file 5.22
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-01-09 12:22:51 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Vasyl Kaigorodov 2015-01-09 10:48:47 EST
It was reported [1] that file versions prior to 5.22 did not limit the number of strings printed, which could lead to a local resource exhaustion and denial of service.

Upstream fix:
https://github.com/file/file/commit/65437cee25199dbd385fb35901bc0011e164276c

This issue seems to be introduced here:
https://github.com/file/file/commit/c8451af8ab0c2e2a93ce93b9c68257d31576cc85
which ended up in 5.16 release.

[1]: http://mx.gw.com/pipermail/file/2014/001654.html
Comment 1 Vasyl Kaigorodov 2015-01-09 10:49:09 EST
Created file tracking bugs for this issue:

Affects: fedora-all [bug 1180643]
Comment 3 Francisco Alonso 2015-03-30 10:54:33 EDT
*** Bug 1175083 has been marked as a duplicate of this bug. ***
Comment 5 Tomas Hoger 2015-11-27 06:38:15 EST
Not Red Hat product was affected by this issue.

Note You need to log in before you can comment on or make changes to this bug.