Format: 1.8 Date: Wed, 13 Jun 2018 14:45:30 -0400 Source: file Binary: file file-dbg libmagic1 libmagic-dev python-magic python3-magic Architecture: i386 all Version: 1:5.14-2ubuntu3.4 Distribution: trusty Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: file - Determines file type using "magic" numbers file-dbg - Determines file type using "magic" numbers (debug) libmagic-dev - File type determination library using "magic" numbers (developmen libmagic1 - File type determination library using "magic" numbers python-magic - File type determination library using "magic" numbers (Python bin python3-magic - File type determination library using "magic" numbers (Python 3 b Changes: file (1:5.14-2ubuntu3.4) trusty-security; urgency=medium . * SECURITY UPDATE: denial of service via large number of notes or long string - debian/patches/CVE-2014-962x-pre*.patch: backport pre-requisite code changes. - debian/patches/CVE-2014-962x-1.patch: add a limit to the number of ELF notes processed in doc/file.man, doc/libmagic.man, src/apprentice.c, src/elfclass.h, src/file.c, src/file.h, src/file_opts.h, src/magic.c, src/magic.h.in, src/readelf.c. - debian/patches/CVE-2014-962x-2.patch: limit string printing to 100 chars, and add flags in src/readelf.c. - CVE-2014-9620 - CVE-2014-9621 * SECURITY UPDATE: denial of service via crafted ELF file - debian/patches/CVE-2014-9653.patch: bail out on partial reads in src/readelf.c. - CVE-2014-9653 * SECURITY UPDATE: memory corruption in file_check_mem. - debian/patches/CVE-2015-8865.patch: properly calculate length in src/funcs.c. - CVE-2015-8865 * SECURITY UPDATE: out-of-bounds read via crafted ELF file - debian/patches/CVE-2018-10360.patch: add bounds check to src/readelf.c. - CVE-2018-10360 Checksums-Sha1: 7acfc7f6aa852efa995c2833fe678304f0f47545 19134 file_5.14-2ubuntu3.4_i386.deb f572a40503088ffdbf8c3e12180b58c31adb411e 127502 file-dbg_5.14-2ubuntu3.4_i386.deb ab9885036e10baadfaba473e8cebaafddf7bba06 185514 libmagic1_5.14-2ubuntu3.4_i386.deb 226b0265761881da619fb3c4a11d27c3da20386a 61176 libmagic-dev_5.14-2ubuntu3.4_i386.deb 91230812a3c60d03e193e6fec8c0a8ad2327661a 4522 python-magic_5.14-2ubuntu3.4_all.deb c0603ebfcf3f9dc87d85a8337bb6f7617880ebb7 4576 python3-magic_5.14-2ubuntu3.4_all.deb d2e0c908cf59541b7eb2230a7415146fafa5b124 924 file-dbgsym_5.14-2ubuntu3.4_i386.ddeb c9809d9d1b3d3d7281b0fb9e4f3636b25f445b14 876 libmagic1-dbgsym_5.14-2ubuntu3.4_i386.ddeb 212983d99eaa3e79e7d86467b1f5f51ec7baf1db 902 libmagic-dev-dbgsym_5.14-2ubuntu3.4_i386.ddeb Checksums-Sha256: 21cfa9255643bfdf8d6b2f6a8d39a2a221231c985b8c18cf1b4e3b34826f8818 19134 file_5.14-2ubuntu3.4_i386.deb eaae127a8650f12dbbcf9bf9ddaff289f1de3ec4242c84285e964c27d810d33a 127502 file-dbg_5.14-2ubuntu3.4_i386.deb dfef71d9274b63932f1adc269d043c07b852a31e1392a4a7a919ae7275b606fd 185514 libmagic1_5.14-2ubuntu3.4_i386.deb 07639aa677b146f09e3099e8eaad4548f8d57ec9d01fc46012cff2d95e262fa9 61176 libmagic-dev_5.14-2ubuntu3.4_i386.deb 228a8e75279e66f0f5a0997ca218069d78ebc8345d9f8038e3e1ab3c92c7a407 4522 python-magic_5.14-2ubuntu3.4_all.deb e070e0bf44fe5a45b3bc56428103c3511c32bc3f3cc3f0703e4240ace00e78ad 4576 python3-magic_5.14-2ubuntu3.4_all.deb a27e916faca7b7d13c9821c2bf90c1144cd10167d06098a3e2f05ba5bcc954be 924 file-dbgsym_5.14-2ubuntu3.4_i386.ddeb 504c7d3882ce691fd6f764846a95c9a6aa3483985fe5eb577dbe1eb042a38c07 876 libmagic1-dbgsym_5.14-2ubuntu3.4_i386.ddeb ecb982a4021034cc1321fd0584196503e88a074abf4e54945ddc7ce7d68c2a9f 902 libmagic-dev-dbgsym_5.14-2ubuntu3.4_i386.ddeb Files: 7bc9c37d06b654c79378fdfb9e74a6a6 19134 utils standard file_5.14-2ubuntu3.4_i386.deb 6f76c0cd8236436285a124c1e4c81061 127502 debug extra file-dbg_5.14-2ubuntu3.4_i386.deb 03ceac368534419a0aa6abc829045116 185514 libs standard libmagic1_5.14-2ubuntu3.4_i386.deb 8358da75bc94ef832cd8129303bea531 61176 libdevel optional libmagic-dev_5.14-2ubuntu3.4_i386.deb 25399dc5720c0d0a4a1dc70d6f710f27 4522 python optional python-magic_5.14-2ubuntu3.4_all.deb 06cf81cd554f805fae4a672f17fff9f1 4576 python optional python3-magic_5.14-2ubuntu3.4_all.deb c8e70d246cca65d26eac73277eb80ac1 924 utils extra file-dbgsym_5.14-2ubuntu3.4_i386.ddeb 5cf70ca9c966c17f44cab364abd45dd6 876 libs extra libmagic1-dbgsym_5.14-2ubuntu3.4_i386.ddeb 1d10ca513c205aa633f1d6744bbd6719 902 libdevel extra libmagic-dev-dbgsym_5.14-2ubuntu3.4_i386.ddeb Original-Maintainer: Luk Claes