3.6
CVSSv2

CVE-2019-8906

Published: 18/02/2019 Updated: 09/12/2021
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 4.4 | Impact Score: 2.5 | Exploitability Score: 1.8
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

It exists that file incorrectly handled certain malformed ELF files. An attacker could use this issue to cause a denial of service, or possibly execute arbitrary code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

file project file 5.35

canonical ubuntu linux 18.04

canonical ubuntu linux 16.04

canonical ubuntu linux 18.10

opensuse leap 42.3

opensuse leap 15.0

apple mac os x

apple watchos

apple tvos

apple iphone os

Vendor Advisories

Several security issues were fixed in file ...
Debian Bug report logs - #922968 file: CVE-2019-8905 CVE-2019-8907 Package: src:file; Maintainer for src:file is Christoph Biedl <debianaxhn@manchmalin-ulmde>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 22 Feb 2019 13:09:02 UTC Severity: important Tags: security, upstream Found in version fi ...
Debian Bug report logs - #922967 file: CVE-2019-8904 Package: src:file; Maintainer for src:file is Christoph Biedl <debianaxhn@manchmalin-ulmde>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 22 Feb 2019 12:51:01 UTC Severity: important Tags: security, upstream Found in version file/1:535-2 Fi ...
Debian Bug report logs - #922969 file: CVE-2019-8906 Package: src:file; Maintainer for src:file is Christoph Biedl <debianaxhn@manchmalin-ulmde>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 22 Feb 2019 13:12:02 UTC Severity: important Tags: security, upstream Found in version file/1:535-2 Fi ...
do_bid_note in readelfc in libmagica has a stack-based buffer over-read, related to file_printf and file_vprintf (CVE-2019-8904) do_core_note in readelfc in libmagica has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360 (CVE-2019-8905) do_core_note in readelfc in libmagica allows rem ...
do_core_note in readelfc in libmagica in file 535 has an out-of-bounds read because memcpy is misused ...