The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large number of (1) program or (2) section headers or (3) invalid capabilities. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-8116