Ubuntu Security Notice 439-1 – Jean-Sebastien Guay-Leroux discovered that “file” did not correctly check the size of allocated heap memory. If a user were tricked into examining a specially crafted file with the “file” utility, a remote attacker could execute arbitrary code with user privileges.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/55338/USN-439-1.txt
Source: https://packetstormsecurity.com/files/55338/Ubuntu-Security-Notice-439-1.html

