PT-2019-5656 · File+2 · File+2

Spinpx

·

Published

2019-02-18

·

Updated

2021-12-09

·

CVE-2019-8905

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions file version 5.35
Description The issue is related to a stack-based buffer over-read in the do core note function in readelf.c in libmagic.a. This can be exploited by a remote attacker to impact the confidentiality, integrity, and availability of protected information. The vulnerability is distinct from previous issues and is associated with the file printable function.
Recommendations For file version 5.35, consider updating to a newer version that addresses this issue, as the current version has a known stack-based buffer over-read vulnerability in the do core note function. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04827
CVE-2019-8905
DLA-1698-1
DLA-1698-2
MGASA-2019-0118
OPENSUSE-SU-2019:0345-1
OPENSUSE-SU-2019_0345-1
OPENSUSE-SU-2019_1197-1
SUSE-SU-2019:0571-1
SUSE-SU-2019:0839-1
USN-3911-1
USN-3911-2

Affected Products

Suse
Ubuntu
File