ArchLinux: 201411-9: file: denial of service through out-of-bounds read
Summary
An out-of-bounds read flaw was found in file's donote() function in the way the file utility determined the note headers of a elf file. This could possibly lead to file executable crash.
Resolution
Upgrade to 5.20-2.
# pacman -Syu "file>=5.20-2"
The problems have been fixed upstream [0] but no release version is
available yet.
References
[0] https://github.com/file/file/commit/39c7ac1106 https://access.redhat.com/security/cve/CVE-2014-3710 https://bugzilla.redhat.com/show_bug.cgi?id=1155071 https://bugs.archlinux.org/task/42759
Workaround
None.