Описание
cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
Отчет
This issue affects the file
package as shipped with Red Hat Enterprise Linux 8. However, this flaw has been rated as having a security impact of Moderate because it is only exploitable if the 32bit version is used, for example when an application uses the 32bit version of libmagic.so.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | file | Not affected | ||
Red Hat Enterprise Linux 5 | php53 | Not affected | ||
Red Hat Enterprise Linux 6 | file | Not affected | ||
Red Hat Enterprise Linux 6 | php | Not affected | ||
Red Hat Enterprise Linux 7 | file | Not affected | ||
Red Hat Enterprise Linux 7 | php | Not affected | ||
Red Hat Software Collections | rh-php70-php | Not affected | ||
Red Hat Software Collections | rh-php71-php | Not affected | ||
Red Hat Enterprise Linux 8 | file | Fixed | RHSA-2021:4374 | 09.11.2021 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.8 High
CVSS3
Связанные уязвимости
cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
cdf_read_property_info in cdf.c in file through 5.37 does not restrict ...
EPSS
7.8 High
CVSS3