file before 5.19 does not properly restrict the amount of data readduring a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7345.
NOTE: The following CVSS v2.0 metrics and score provided are preliminary and subject to review.
|Base Score:||4.3||Base Metrics:||AV:N/AC:M/Au:N/C:N/I:N/A:P|
|Access Vector:||Network||Attack Complexity:||Medium|
|Authentication:||None required||Confidentiality Impact:||None|
|Integrity Impact:||None||Availability Impact:||Partial|
|Oracle Linux version 6 (file)||ELSA-2016-0760||2016-05-12|
|Oracle Linux version 7 (file)||ELSA-2015-2155||2015-11-23|
|Oracle Linux version 7 (php)||ELSA-2014-1327||2014-09-30|
|Oracle VM version 3.3 (file)||OVMSA-2016-0050||2016-05-13|
|Oracle VM version 3.4 (file)||OVMSA-2016-0050||2016-05-13|
This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team