cbcvebase.
CVE-2019-8905
published 2019-02-18

CVE-2019-8905: do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than…

medium4.4CVSS 3.1
AVLACLPRLUINSUCLINAL
do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360.

Affected

12 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianfile< file 1:5.35-3 (bookworm)file 1:5.35-3 (bookworm)
file_projectfile
file_projectfile>= 0 < 1:5.35-31:5.35-3
file_projectfile>= 0 < 1:5.35-31:5.35-3
file_projectfile>= 0 < 1:5.35-31:5.35-3
file_projectfile>= 0 < 1:5.35-31:5.35-3
opensuseleap
opensuseleap

CVSS provenance

nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
osv6.5MEDIUM