CVE-2004-1304
published 2005-01-10CVE-2004-1304: Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF file.
PriorityP345critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
11.40%
95.5th percentile
Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF file.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | file | < file 4.12 (bookworm) | file 4.12 (bookworm) |
| file | file | — | — |
| file | file | — | — |
| file | file | — | — |
| file | file | — | — |
| file | file | — | — |
| file | file | — | — |
| file | file | — | — |
| file | file | — | — |
| file | file | — | — |
| file | file | — | — |
| file | file | — | — |
| file | file | — | — |
| file_project | file | >= 0 < 4.12 | 4.12 |
| file_project | file | >= 0 < 4.12 | 4.12 |
| file_project | file | >= 0 < 4.12 | 4.12 |
| file_project | file | >= 0 < 4.12 | 4.12 |
| trustix | secure_linux | — | — |
| trustix | secure_linux | — | — |
| trustix | secure_linux | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w22m-7gfq-73mf: Stack-based buffer overflow in the ELF header parsing code in file before 4
ghsa_unreviewed·2022-04-29
CVE-2004-1304 [HIGH] GHSA-w22m-7gfq-73mf: Stack-based buffer overflow in the ELF header parsing code in file before 4
Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF file.
OSV
CVE-2004-1304: Stack-based buffer overflow in the ELF header parsing code in file before 4
osv·2005-01-10·CVSS 10.0
CVE-2004-1304 [CRITICAL] CVE-2004-1304: Stack-based buffer overflow in the ELF header parsing code in file before 4
Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF file.
Debian
CVE-2004-1304: file - Stack-based buffer overflow in the ELF header parsing code in file before 4.12 a...
vendor_debian·2004·CVSS 10.0
CVE-2004-1304 [CRITICAL] CVE-2004-1304: file - Stack-based buffer overflow in the ELF header parsing code in file before 4.12 a...
Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF file.
Scope: local
bookworm: resolved (fixed in 4.12)
bullseye: resolved (fixed in 4.12)
forky: resolved (fixed in 4.12)
sid: resolved (fixed in 4.12)
trixie: resolved (fixed in 4.12)
No detection rules found.
Bugzilla
CAN-2004-1304 File ELF Header Unspecified Buffer Overflow
bugzilla·2005-04-25
[MEDIUM] CAN-2004-1304 File ELF Header Unspecified Buffer Overflow
CAN-2004-1304 File ELF Header Unspecified Buffer Overflow
+++ This bug was initially created as a clone of Bug #152865 +++
04.48.16 CVE: Not Available
Platform: Unix
Title: File ELF Header Unspecified Buffer Overflow
Description: The Unix file command is affected by a buffer overflow
vulnerability. This issue is due to a failure of the application to
properly validate string lengths in the affected files prior to
copying them into static process buffers. This can be leveraged by an
attacker to execute hostile code on the vulnerable system.
Ref: http://www.securityfocus.com/advisories/7566
------- Additional Comments From [email protected] 2004-12-14 08:40:43
----
gentoo has an advisory on it, now, too:
http://www.gentoo.org/security/en/glsa/glsa-200412-07.xml
All versions
Bugzilla
CAN-2004-1304, File ELF Header Unspecified Buffer Overflow
bugzilla·2004-12-07
[MEDIUM] CAN-2004-1304, File ELF Header Unspecified Buffer Overflow
CAN-2004-1304, File ELF Header Unspecified Buffer Overflow
04.48.16 CVE: Not Available
Platform: Unix
Title: File ELF Header Unspecified Buffer Overflow
Description: The Unix file command is affected by a buffer overflow
vulnerability. This issue is due to a failure of the application to
properly validate string lengths in the affected files prior to
copying them into static process buffers. This can be leveraged by an
attacker to execute hostile code on the vulnerable system.
Ref: http://www.securityfocus.com/advisories/7566
------- Additional Comments From [email protected] 2004-12-14 08:40:43 ----
gentoo has an advisory on it, now, too:
http://www.gentoo.org/security/en/glsa/glsa-200412-07.xml
------- Additional Comments From [email protected] 2005-02-15 07:21:09 ----
T
http://securitytracker.com/id?1012433http://www.gentoo.org/security/en/glsa/glsa-200412-07.xmlhttp://www.securityfocus.com/bid/11771http://www.trustix.net/errata/2004/0063/https://exchange.xforce.ibmcloud.com/vulnerabilities/18368http://securitytracker.com/id?1012433http://www.gentoo.org/security/en/glsa/glsa-200412-07.xmlhttp://www.securityfocus.com/bid/11771http://www.trustix.net/errata/2004/0063/https://exchange.xforce.ibmcloud.com/vulnerabilities/18368
2005-01-10
Published