CVE-2014-1943

Advisory lineage Upstream: 0 Downstream: 12
Modified
Published: 18 Feb 2014, 19:00
Last modified:06 Aug 2024, 09:58

Vulnerability Summary

Overall Risk (default)
medium
25/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
24.89% HIGH
25% probability +3.68%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

18 Feb 2014, 19:00
Published
Vulnerability first disclosed
06 Aug 2024, 09:58
Last Modified
Vulnerability information updated

Description

Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted indirect offset value in the magic of a file.

CVSS Metrics

  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 24.89% Percentile: 96%

Techniques & Countermeasures

  • CWE-755Improper Handling of Exceptional Conditions

    The product does not handle or incorrectly handles an exceptional condition.

Affected Systems

  • canonicalubuntu_linux

    10.04 | 12.04 | 12.10 | 13.10

  • debiandebian_linux

    6.0 | 7.0

  • fine_free_file_projectfine_free_file

    < 5.17

  • UnknownPHP

    ≥ 5.4.0, < 5.4.26 | ≥ 5.5.0, < 5.5.10

References (14)