Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-8906

Опубликовано: 03 янв. 2019
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.

A vulnerability has been identified in the File Project, specifically in the do_core_note function within readelf.c of libmagic.a where, an out-of-bounds read, can be exploited by a local attacker using a specially crafted file which could result in a denial of service or leakage of sensitive information.

Отчет

This vulnerability was rated as LOW severity because its exploitation requires a local attacker to use a specially crafted file and it results in temporary application crashes or exposure of limited information, it does not allow remote code execution or system compromise.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5fileNot affected
Red Hat Enterprise Linux 5php53Not affected
Red Hat Enterprise Linux 6fileNot affected
Red Hat Enterprise Linux 6phpNot affected
Red Hat Enterprise Linux 7fileNot affected
Red Hat Enterprise Linux 7phpNot affected
Red Hat Enterprise Linux 8fileFix deferred
Red Hat Software Collectionsrh-php72-phpNot affected
Red Hat Software Collectionsrh-php73-phpNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1679175file: out-of-bounds read in do_core_note in readelf.c

EPSS

Процентиль: 39%
0.00474
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
ubuntu
больше 7 лет назад

do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.

CVSS3: 4.4
nvd
больше 7 лет назад

do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.

CVSS3: 4.4
debian
больше 7 лет назад

do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bou ...

CVSS3: 4.4
github
больше 4 лет назад

do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.

CVSS3: 8.8
fstec
больше 7 лет назад

Уязвимость функции do_core_note утилиты для определения типа заданных файлов File, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 39%
0.00474
Низкий

4.4 Medium

CVSS3