CVE-2019-18218
published 2019-10-21CVE-2019-18218: cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte…
PriorityP341high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.85%
76.7th percentile
cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | file | < file 1:5.37-6 (bookworm) | file 1:5.37-6 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| file_project | file | <= 5.37 | — |
| file_project | file | >= 0 < 1:5.37-6 | 1:5.37-6 |
| file_project | file | >= 0 < 1:5.37-6 | 1:5.37-6 |
| file_project | file | >= 0 < 1:5.37-6 | 1:5.37-6 |
| file_project | file | >= 0 < 1:5.37-6 | 1:5.37-6 |
| netapp | active_iq_unified_manager | >= 7.3 | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
file vulnerability
vendor_ubuntu·2019-10-31
CVE-2019-18218 file vulnerability
Title: file vulnerability
Summary: file could be made to crash or run programs if it opened a specially
crafted file.
USN-4172-1 fixed a vulnerability in file. This update provides
the corresponding update for Ubuntu 12.04 ESM Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that file incorrectly handled certain malformed files. An
attacker could use this issue to cause a denial of service, or possibly
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
file vulnerability
vendor_ubuntu·2019-10-30
CVE-2019-18218 file vulnerability
Title: file vulnerability
Summary: file could be made to crash or run programs if it opened a specially
crafted file.
It was discovered that file incorrectly handled certain malformed files. An
attacker could use this issue to cause a denial of service, or possibly
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
file: heap-based buffer overflow in cdf_read_property_info in cdf.c
vendor_redhat·2019-08-26·CVSS 7.8
CVE-2019-18218 [HIGH] CWE-122 file: heap-based buffer overflow in cdf_read_property_info in cdf.c
file: heap-based buffer overflow in cdf_read_property_info in cdf.c
cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
Statement: This issue affects the `file` package as shipped with Red Hat Enterprise Linux 8. However, this flaw has been rated as having a security impact of Moderate because it is only exploitable if the 32bit version is used, for example when an application uses the 32bit version of libmagic.so.
Package: file (Red Hat Enterprise Linux 5) - Not affected
Package: php53 (Red Hat Enterprise Linux 5) - Not affected
Package: file (Red Hat Enterprise Linux 6) - Not affected
Package: php (Red Hat Enterprise Linux 6) - Not affected
Package: file (R
Debian
CVE-2019-18218: file - cdf_read_property_info in cdf.c in file through 5.37 does not restrict the numbe...
vendor_debian·2019·CVSS 7.8
CVE-2019-18218 [HIGH] CVE-2019-18218: file - cdf_read_property_info in cdf.c in file through 5.37 does not restrict the numbe...
cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
Scope: local
bookworm: resolved (fixed in 1:5.37-6)
bullseye: resolved (fixed in 1:5.37-6)
forky: resolved (fixed in 1:5.37-6)
sid: resolved (fixed in 1:5.37-6)
trixie: resolved (fixed in 1:5.37-6)
GHSA
GHSA-gg3j-j3hx-hjx5: cdf_read_property_info in cdf
ghsa_unreviewed·2022-05-24
CVE-2019-18218 [HIGH] CWE-787 GHSA-gg3j-j3hx-hjx5: cdf_read_property_info in cdf
cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
OSV
CVE-2019-18218: cdf_read_property_info in cdf
osv·2019-10-21·CVSS 7.8
CVE-2019-18218 [HIGH] CVE-2019-18218: cdf_read_property_info in cdf
cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-18218 file: heap-based buffer overflow in cdf_read_property_info in cdf.c [fedora-all]
bugzilla·2019-10-24·CVSS 7.8
CVE-2019-18218 [HIGH] CVE-2019-18218 file: heap-based buffer overflow in cdf_read_property_info in cdf.c [fedora-all]
CVE-2019-18218 file: heap-based buffer overflow in cdf_read_property_info in cdf.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2019-18218 file: heap-based buffer overflow in cdf_read_property_info in cdf.c
bugzilla·2019-10-24·CVSS 7.8
CVE-2019-18218 [HIGH] CVE-2019-18218 file: heap-based buffer overflow in cdf_read_property_info in cdf.c
CVE-2019-18218 file: heap-based buffer overflow in cdf_read_property_info in cdf.c
cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
Reference:
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16780
Upstream patch:
https://github.com/file/file/commit/46a8443f76cec4b41ec736eca396984c74664f84
Discussion:
Created file tracking bugs for this issue:
Affects: fedora-all [bug 1765273]
---
A git bisect shows that this was introduced by https://github.com/file/file/commit/393555f2f3a6ba16cdedf6d65ac373700afdd769
---
The root issue is an integer overflow in the cdf_grow_info() function:
"size_t newcount = *maxcount + incr;" can wrap around, causing newcount t
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00044.htmlhttps://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16780https://github.com/file/file/commit/46a8443f76cec4b41ec736eca396984c74664f84https://lists.debian.org/debian-lts-announce/2019/10/msg00032.htmlhttps://lists.debian.org/debian-lts-announce/2021/07/msg00008.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CV6PFCEYHYALMTT45QE2U5C5TEJZQPXJ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D6BJVGXSCC6NMIAWX36FPWHEIFON3OSE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VBK6XOJR6OVWT2FUEBO7V7KCOSSLAP52/https://security.gentoo.org/glsa/202003-24https://security.netapp.com/advisory/ntap-20200115-0001/https://usn.ubuntu.com/4172-1/https://usn.ubuntu.com/4172-2/https://www.debian.org/security/2019/dsa-4550http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00044.htmlhttps://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16780https://github.com/file/file/commit/46a8443f76cec4b41ec736eca396984c74664f84https://lists.debian.org/debian-lts-announce/2019/10/msg00032.htmlhttps://lists.debian.org/debian-lts-announce/2021/07/msg00008.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CV6PFCEYHYALMTT45QE2U5C5TEJZQPXJ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D6BJVGXSCC6NMIAWX36FPWHEIFON3OSE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VBK6XOJR6OVWT2FUEBO7V7KCOSSLAP52/https://security.gentoo.org/glsa/202003-24https://security.netapp.com/advisory/ntap-20200115-0001/https://usn.ubuntu.com/4172-1/https://usn.ubuntu.com/4172-2/https://www.debian.org/security/2019/dsa-4550
2019-10-21
Published