SB2014030315 - Resource exhaustion in file (Alpine package)
Published: March 3, 2014
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource exhaustion (CVE-ID: CVE-2014-1943)
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite recursion when insufficient validation of user-supplied input. A local attacker can trigger CPU consumption and cause the service to crash.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=67acd4b824737a8ca2898d3eea7fbb4d3aeff8ba
- https://git.alpinelinux.org/aports/commit/?id=f574def4a7f0f1b99bed17cc4f9e96821afa2e85
- https://git.alpinelinux.org/aports/commit/?id=070ac1e4fedc510410ffb8e85eb7ae0d6b20d1b1
- https://git.alpinelinux.org/aports/commit/?id=2bb44c021f13a71d3069579c18934f47bbf319c6