Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-8905

Опубликовано: 18 фев. 2019
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360.

A vulnerability was found in the "File" project where a stack-based buffer over-read exists in the do_core_note function within readelf.c of libmagic.a, by using a specially crafted file the attacker could access sensitive information or cause a denial of service.

Отчет

This vulnerability is rated as Moderate severity because it allows a stack-buffer over-read in the do_core_note funtion within readelf.c in libmagic.a. This issue, realted to file_printable, may lead to application crashes or exposure of sensitive information.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5fileNot affected
Red Hat Enterprise Linux 5php53Not affected
Red Hat Enterprise Linux 6fileNot affected
Red Hat Enterprise Linux 6phpNot affected
Red Hat Enterprise Linux 7fileNot affected
Red Hat Enterprise Linux 7phpNot affected
Red Hat Enterprise Linux 8fileWill not fix
Red Hat Software Collectionsrh-php72-phpNot affected
Red Hat Software Collectionsrh-php73-phpNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1679181file: stack-based buffer over-read in do_core_note in readelf.c

EPSS

Процентиль: 38%
0.00457
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
ubuntu
больше 7 лет назад

do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360.

CVSS3: 4.4
nvd
больше 7 лет назад

do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360.

CVSS3: 4.4
debian
больше 7 лет назад

do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based ...

CVSS3: 4.4
github
больше 4 лет назад

do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360.

CVSS3: 8.8
fstec
больше 7 лет назад

Уязвимость функции do_bid_note утилиты для определения типа заданных файлов File, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 38%
0.00457
Низкий

4.4 Medium

CVSS3

Уязвимость CVE-2019-8905