6.8
CVSSv2

CVE-2019-8907

Published: 18/02/2019 Updated: 24/08/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

do_core_note in readelf.c in libmagic.a in file 5.35 allows remote malicious users to cause a denial of service (stack corruption and application crash) or possibly have unspecified other impact.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

file project file 5.35

debian debian linux 8.0

opensuse leap 15.0

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 18.10

Vendor Advisories

Several security issues were fixed in file ...
do_core_note in readelfc in libmagica in file 535 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified other impact ...
Debian Bug report logs - #922967 file: CVE-2019-8904 Package: src:file; Maintainer for src:file is Christoph Biedl <debianaxhn@manchmalin-ulmde>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 22 Feb 2019 12:51:01 UTC Severity: important Tags: security, upstream Found in version file/1:535-2 Fi ...
Debian Bug report logs - #922969 file: CVE-2019-8906 Package: src:file; Maintainer for src:file is Christoph Biedl <debianaxhn@manchmalin-ulmde>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 22 Feb 2019 13:12:02 UTC Severity: important Tags: security, upstream Found in version file/1:535-2 Fi ...
Debian Bug report logs - #922968 file: CVE-2019-8905 CVE-2019-8907 Package: src:file; Maintainer for src:file is Christoph Biedl <debianaxhn@manchmalin-ulmde>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 22 Feb 2019 13:09:02 UTC Severity: important Tags: security, upstream Found in version fi ...
do_bid_note in readelfc in libmagica has a stack-based buffer over-read, related to file_printf and file_vprintf (CVE-2019-8904 ) do_core_note in readelfc in libmagica has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360 (CVE-2019-8905 ) do_core_note in readelfc in libmagica allows ...
Arch Linux Security Advisory ASA-201903-5 ========================================= Severity: High Date : 2019-03-03 CVE-ID : CVE-2019-8904 CVE-2019-8905 CVE-2019-8906 CVE-2019-8907 Package : file Type : multiple issues Remote : Yes Link : securityarchlinuxorg/AVG-907 Summary ======= The package file before version 536-1 is ...

Mailing Lists

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] file (SSA:2019-054-01) New file packages are available for Slackware 140, 141, 142, and -current to fix security issues Here are the details from the Slackware 142 ChangeLog: +--------------------------+ patches/packages/file-536-i586-1_slack142txz: Upgraded Fix out ...