DSA-4550-1 file -- security update

Related Vulnerabilities: CVE-2019-18218  

A buffer overflow was found in file, a file type classification tool, which may result in denial of service or potentially the execution of arbitrary code if a malformed CDF (Composite Document File) file is processed. For the oldstable distribution (stretch), this problem has been fixed in version 1:5.30-1+deb9u3. For the stable distribution (buster), this problem has been fixed in version 1:5.35-4+deb10u1. We recommend that you upgrade your file packages. For the detailed security status of file please refer to its security tracker page at: https://security-tracker.debian.org/tracker/file

Debian Security Advisory

DSA-4550-1 file -- security update

Date Reported:
25 Oct 2019
Affected Packages:
file
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2019-18218.
More information:

A buffer overflow was found in file, a file type classification tool, which may result in denial of service or potentially the execution of arbitrary code if a malformed CDF (Composite Document File) file is processed.

For the oldstable distribution (stretch), this problem has been fixed in version 1:5.30-1+deb9u3.

For the stable distribution (buster), this problem has been fixed in version 1:5.35-4+deb10u1.

We recommend that you upgrade your file packages.

For the detailed security status of file please refer to its security tracker page at: https://security-tracker.debian.org/tracker/file