Vulnerability Details CVE-2013-7345
The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses multiple wildcards with unlimited repetitions, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted ASCII file that triggers a large amount of backtracking, as demonstrated via a file with many newline characters.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.015
EPSS Ranking 80.4%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2013-7345
-
cpe:2.3:a:christos_zoulas:file:5.00
-
cpe:2.3:a:christos_zoulas:file:5.01
-
cpe:2.3:a:christos_zoulas:file:5.02
-
cpe:2.3:a:christos_zoulas:file:5.03
-
cpe:2.3:a:christos_zoulas:file:5.04
-
cpe:2.3:a:christos_zoulas:file:5.05
-
cpe:2.3:a:christos_zoulas:file:5.06
-
cpe:2.3:a:christos_zoulas:file:5.07
-
cpe:2.3:a:christos_zoulas:file:5.08
-
cpe:2.3:a:christos_zoulas:file:5.09
-
cpe:2.3:a:christos_zoulas:file:5.10
-
cpe:2.3:a:christos_zoulas:file:5.11
-
cpe:2.3:a:christos_zoulas:file:5.12
-
cpe:2.3:a:christos_zoulas:file:5.13
-
cpe:2.3:a:christos_zoulas:file:5.14
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:o:debian:debian_linux:6.0
-
cpe:2.3:o:debian:debian_linux:7.0
-
cpe:2.3:o:debian:debian_linux:8.0