PT-2019-5656 · File+2 · File+2
Spinpx
·
Published
2019-02-18
·
Updated
2021-12-09
·
CVE-2019-8905
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
file version 5.35
Description
The issue is related to a stack-based buffer over-read in the do core note function in readelf.c in libmagic.a. This can be exploited by a remote attacker to impact the confidentiality, integrity, and availability of protected information. The vulnerability is distinct from previous issues and is associated with the file printable function.
Recommendations
For file version 5.35, consider updating to a newer version that addresses this issue, as the current version has a known stack-based buffer over-read vulnerability in the do core note function.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse
Ubuntu
File