file CVE-2014-8117 Denial of Service Vulnerability
BID:71692
Info
file CVE-2014-8117 Denial of Service Vulnerability
| Bugtraq ID: | 71692 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2014-8117 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 16 2014 12:00AM |
| Updated: | Sep 21 2016 03:00PM |
| Credit: | Thomas Jarosch of Intra2net AG |
| Vulnerable: |
Ubuntu Ubuntu Linux 14.10 Ubuntu Ubuntu Linux 14.04 LTS Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Pexip Pexip Infinity 8.0 Pexip Pexip Infinity 7.0 Pexip Pexip Infinity 6.0 Pexip Pexip Infinity 5.0 Pexip Pexip Infinity 4.0 Pexip Pexip Infinity 3.0 Pexip Pexip Infinity 2.0 Pexip Pexip Infinity 1.0 Oracle Linux 0 Oracle Enterprise Linux 7 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 IBM SmartCloud Entry 3.2 Fix Pack 18 IBM SmartCloud Entry 3.2 fix pack 14 IBM SmartCloud Entry 3.2 Fix Pack 11 IBM SmartCloud Entry 3.2 Appliance fix pack 2 IBM SmartCloud Entry 3.2 IBM SmartCloud Entry 3.1 fix pack 13 IBM SmartCloud Entry 3.1 Fix Pack 10 IBM SmartCloud Entry 3.1 IBM SmartCloud Entry 2.4 Appliance fix pack 4 IBM SmartCloud Entry 2.3 Fix Pack 1 IBM SmartCloud Entry 2.3 Appliance fix pack 6 IBM SmartCloud Entry 2.3 Appliance fix pack 4 IBM SmartCloud Entry 2.2 Fix Pack 2 IBM SmartCloud Entry 2.2 Fix Pack 1 IBM SmartCloud Entry 2.2 Appliance fix pack 6 IBM SmartCloud Entry 2.2 Appliance fix pack 4 IBM SmartCloud Entry 2.2 IBM SmartCloud Entry 3.2.0.4 IBM SmartCloud Entry 3.2.0.3 IBM SmartCloud Entry 3.2.0.2 IBM SmartCloud Entry 3.2.0.1 IBM SmartCloud Entry 3.2.0.0 IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 IBM SmartCloud Entry 3.1.0.3 IBM SmartCloud Entry 3.1.0.2 IBM SmartCloud Entry 3.1.0.1 IBM SmartCloud Entry 2.4.0.4 Appliance Fi IBM SmartCloud Entry 2.4.0.4 Appliance Fi IBM SmartCloud Entry 2.4.0.3 Appliance FP IBM SmartCloud Entry 2.4.0 fix pack 1 IBM SmartCloud Entry 2.4.0 IBM SmartCloud Entry 2.3.0.4 Appliance FP IBM SmartCloud Entry 2.3.0.4 Appliance FP IBM SmartCloud Entry 2.3.0.4 Appliance Fi IBM SmartCloud Entry 2.3.0.4 Appliance Fi IBM SmartCloud Entry 2.3.0.3 JRE Update 4 IBM SmartCloud Entry 2.3.0.3 Appliance FP IBM SmartCloud Entry 2.3.0.3 Appliance FP IBM SmartCloud Entry 2.3.0 IBM SmartCloud Entry 2.2.0.4 Appliance Fi IBM SmartCloud Entry 2.2.0.4 Appliance Fi IBM SmartCloud Entry 2.2.0.3 Appliance FP IBM Security Network Protection 5.3.2 IBM Security Network Protection 5.3.1 IBM PowerKVM 3.1 IBM PowerKVM 2.1 Ian Darwin file 5.20 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 AlienVault AlienVault 4.15 AlienVault AlienVault 4.13 AlienVault AlienVault 4.12.1 AlienVault AlienVault 4.12 |
| Not Vulnerable: |
Pexip Pexip Infinity 9.0 IBM PowerKVM 2.1.1 SP3 IBM PowerKVM 2.1.1 Build 65.6 IBM PowerKVM 3.1 Build 3 Ian Darwin file 5.21 AlienVault AlienVault 4.15.1 |
Discussion
file CVE-2014-8117 Denial of Service Vulnerability
file is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause excessive resource consumption, resulting in a denial-of-service condition.
file is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause excessive resource consumption, resulting in a denial-of-service condition.
Exploit / POC
file CVE-2014-8117 Denial of Service Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
file CVE-2014-8117 Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
file CVE-2014-8117 Denial of Service Vulnerability
References:
References:
- Bug 1174606 - (CVE-2014-8117) CVE-2014-8117 file: denial of service issue (resou (Red Hat Bugzilla)
- file Homepage (Ian Darwin)
- file(1): multiple denial of service issues (resource consumption), CVE-2014-8116 (Murray McAllister)
- isg3T1023349 Multiple vulnerabilities in file affect PowerKVM (IBM)
- isg3T1024195:File vulnerabilities affect IBM SmartClound Entry (IBM)
- pexip Security Bulletin: Multiple vulnerabilities (Pexip)
- Ref: linuxbulletinoct2015-2719645 Oracle Linux Bulletin - October 2015 Revision (Oracle)
- Security Advisory, AlienVault v4.15.1 addresses twenty (20) vulnerabilities (AlienVault)
- swg21985753:Multiple vulnerabilities in file affect IBM Security Network Protect (IBM)