Debian-LTS alert DLA-204-1 (file)
| From: | Christoph Biedl <debian.axhn@manchmal.in-ulm.de> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 204-1] file security update | |
| Date: | Sun, 19 Apr 2015 15:06:12 +0200 | |
| Message-ID: | <1429448735@msgid.manchmal.in-ulm.de> |
Package : file Version : 5.04-5+squeeze10 CVE ID : CVE-2014-9653 Debian Bug : 777585 This update fixes the following issue in the file package: CVE-2014-9653 readelf.c does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory access) or possibly have unspecified other impact via a crafted ELF file.
