Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-18218

Опубликовано: 26 авг. 2019
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).

Отчет

This issue affects the file package as shipped with Red Hat Enterprise Linux 8. However, this flaw has been rated as having a security impact of Moderate because it is only exploitable if the 32bit version is used, for example when an application uses the 32bit version of libmagic.so.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5fileNot affected
Red Hat Enterprise Linux 5php53Not affected
Red Hat Enterprise Linux 6fileNot affected
Red Hat Enterprise Linux 6phpNot affected
Red Hat Enterprise Linux 7fileNot affected
Red Hat Enterprise Linux 7phpNot affected
Red Hat Software Collectionsrh-php70-phpNot affected
Red Hat Software Collectionsrh-php71-phpNot affected
Red Hat Enterprise Linux 8fileFixedRHSA-2021:437409.11.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1765272file: heap-based buffer overflow in cdf_read_property_info in cdf.c

EPSS

Процентиль: 44%
0.00216
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 6 лет назад

cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).

CVSS3: 7.8
nvd
почти 6 лет назад

cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).

CVSS3: 7.8
debian
почти 6 лет назад

cdf_read_property_info in cdf.c in file through 5.37 does not restrict ...

suse-cvrf
около 5 лет назад

Security update for file

suse-cvrf
почти 4 года назад

Security update for file

EPSS

Процентиль: 44%
0.00216
Низкий

7.8 High

CVSS3