Summary
The remote host is missing an update to file
announced via advisory DSA 2422-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%202422-1
Insight
The file type identification tool, file, and its associated library, libmagic, do not properly process malformed files in the Composite Document File (CDF) format, leading to crashes.
Note that after this update, file may return different detection results for CDF files (well-formed or not). The new detections are believed to be more accurate.
For the stable distribution (squeeze), this problem has been fixed in version 5.04-5+squeeze1.
We recommend that you upgrade your file packages.
Severity
Classification
-
CVE CVE-2012-1571 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:N/A:P
Related Vulnerabilities