3.6
CVSSv2

CVE-2019-8905

Published: 18/02/2019 Updated: 09/12/2021
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 4.4 | Impact Score: 2.5 | Exploitability Score: 1.8
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

It exists that file incorrectly handled certain malformed ELF files. An attacker could use this issue to cause a denial of service, or possibly execute arbitrary code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 8.0

file project file 5.35

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 18.10

opensuse leap 15.0

opensuse leap 42.3

Vendor Advisories

Several security issues were fixed in file ...
Debian Bug report logs - #922968 file: CVE-2019-8905 CVE-2019-8907 Package: src:file; Maintainer for src:file is Christoph Biedl <debianaxhn@manchmalin-ulmde>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 22 Feb 2019 13:09:02 UTC Severity: important Tags: security, upstream Found in version fi ...
Debian Bug report logs - #922967 file: CVE-2019-8904 Package: src:file; Maintainer for src:file is Christoph Biedl <debianaxhn@manchmalin-ulmde>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 22 Feb 2019 12:51:01 UTC Severity: important Tags: security, upstream Found in version file/1:535-2 Fi ...
Debian Bug report logs - #922969 file: CVE-2019-8906 Package: src:file; Maintainer for src:file is Christoph Biedl <debianaxhn@manchmalin-ulmde>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 22 Feb 2019 13:12:02 UTC Severity: important Tags: security, upstream Found in version file/1:535-2 Fi ...
do_bid_note in readelfc in libmagica has a stack-based buffer over-read, related to file_printf and file_vprintf (CVE-2019-8904) do_core_note in readelfc in libmagica has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360 (CVE-2019-8905) do_core_note in readelfc in libmagica allows rem ...
Impact: Moderate Public Date: 2019-02-18 CWE: CWE-125 Bugzilla: 1679181: CVE-2019-8905 file: stack-base ...
do_core_note in readelfc in libmagica in file 535 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360 ...