Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 14 min 106 bronnen 1 kritiek 1 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2013-7345

MEDIUM · 5.0 CVSS Gepubliceerd:

Beschrijving

The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses multiple wildcards with unlimited repetitions, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted ASCII file that triggers a large amount of backtracking, as demonstrated via a file with many newline characters.

Vendors

Christos Zoulas Php Debian

Affected products

File Php Debian Linux

References