CVE-2019-8905Out-of-bounds Read in Project File

CWE-125Out-of-bounds Read9 documents8 sources
Severity
4.4MEDIUMNVD
CNA6.5OSV6.5
EPSS
0.1%
top 73.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 18
Latest updateMay 13

Description

do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:LExploitability: 1.8 | Impact: 2.5

Affected Packages3 packages

Debianfile_project/file< 1:5.35-3+3
NVDopensuse/leap15.0, 42.3+1

Also affects: Debian Linux 8.0, Ubuntu Linux 16.04, 18.04, 18.10

🔴Vulnerability Details

3
GHSA
GHSA-ffw4-28vr-p4x2: do_core_note in readelf2022-05-13
OSV
CVE-2019-8905: do_core_note in readelf2019-02-18
CVEList
CVE-2019-8905: do_core_note in readelf2019-02-18

📋Vendor Advisories

3
Ubuntu
file vulnerabilities2019-03-18
Red Hat
file: stack-based buffer over-read in do_core_note in readelf.c2019-02-18
Debian
CVE-2019-8905: file - do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer ov...2019

💬Community

2
Bugzilla
CVE-2019-8905 file: stack-based buffer over-read in do_core_note in readelf.c2019-02-20
Bugzilla
CVE-2019-8905 file: stack-based buffer over-read in do_core_note in readelf.c [fedora-all]2019-02-20
CVE-2019-8905 — Out-of-bounds Read in File Project File | cvebase