The ELF parser in file 5.16 through 5.21 allows remote attackers to cause a denial of service via a long string.
{
"binaries": [
{
"binary_name": "file",
"binary_version": "1:5.14-2ubuntu3.4"
},
{
"binary_name": "libmagic-dev",
"binary_version": "1:5.14-2ubuntu3.4"
},
{
"binary_name": "libmagic1",
"binary_version": "1:5.14-2ubuntu3.4"
},
{
"binary_name": "python-magic",
"binary_version": "1:5.14-2ubuntu3.4"
},
{
"binary_name": "python3-magic",
"binary_version": "1:5.14-2ubuntu3.4"
}
],
"availability": "No subscription required"
}