Skip to content

CVE-2013-7345

The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses multiple wildcards with unlimited repetitions, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted ASCII file that triggers a large amount of backtracking, as demonstrated via a file with many newline characters.

Ver en NVD

Severidad

N/A

EPSS

Probabilidad de explotación (próx. 30 días): 0.0113 (1.1%)
Percentil: 78.4%
EPSS: 2026-05-06

Afecta

christos_zoulas:filephp:phpdebian:debian_linux

Descripción técnica

The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses multiple wildcards with unlimited repetitions, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted ASCII file that triggers a large amount of backtracking, as demonstrated via a file with many newline characters.

Publicada: 24/3/2014, 16:31:08
Última modificación: 6/5/2026, 22:30:45

Referencias

InicioEventosBlogRecursosEquipo