Debian Security Advisory

DLA-460-1 file -- LTS security update

Date Reported:
07 May 2016
Affected Packages:
file
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2015-8865.
More information:

A malformed magic file could trigger a segmentation fault and thus crash applications due to a buffer over-write in the file_check_mem function.

For Debian 7 Wheezy, this problem has been fixed in version 5.11-2+deb7u9.

We recommend that you upgrade your file packages.