——————————————————————————–
Fedora Update Notification
FEDORA-2014-3606
2014-03-08 02:57:39
——————————————————————————–
Name : file
Product : Fedora 20
Version : 5.14
Release : 17.fc20
URL : http://www.darwinsys.com/file/
Summary : A utility for determining file types
Description :
The file command is used to identify a particular file according to the
type of data contained by the file. File can identify many different
file types, including ELF binaries, system libraries, RPM packages, and
different graphics formats.
——————————————————————————–
Update Information:
Fix for CVE-2014-2270.
——————————————————————————–
ChangeLog:
* Fri Mar 7 2014 Jan Kaluza <jkaluza@redhat.com> – 5.14-17
– fix #1073555 – fix for CVE-2014-2270
* Tue Feb 25 2014 Jan Kaluza <jkaluza@redhat.com> – 5.14-16
– fix potential memory leak introduced in previous commit
* Tue Feb 18 2014 Jan Kaluza <jkaluza@redhat.com> – 5.14-15
– fix #1065837 – fix for CVE-2014-1943
* Wed Jan 15 2014 Jan Kaluza <jkaluza@redhat.com> – 5.14-14
– fix #1051598 – reverse the order of shebang vs. package keyword detection
in Perl by increasing strength of all Perl patterns
* Mon Sep 9 2013 Jan Kaluza <jkaluza@redhat.com> – 5.14-13
– fix #1001689 – fix segfault when calling magic_load twice
——————————————————————————–
References:
[ 1 ] Bug #1072220 – CVE-2014-2270 file: out-of-bounds memory access when parsing Portable Executable (PE) format files
https://bugzilla.redhat.com/show_bug.cgi?id=1072220
——————————————————————————–
This update can be installed with the “yum” update program. Use
su -c ‘yum update file’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce