cbcvebase.
CVE-2019-8906
published 2019-02-18

CVE-2019-8906: do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.

medium4.4CVSS 3.1
AVLACLPRLUINSUCLINAL
do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.

Affected

19 ranges
VendorProductVersion rangeFixed in
appleios
appleiphone_os< 12.212.2
applemac_os_x< 10.14.410.14.4
applemacos_mojave_10.14.4_security_update_2019-002_high_sierra_security_update_2019-0
appletvos< 12.212.2
appletvos
applewatchos< 5.25.2
applewatchos
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianfile< file 1:5.35-3 (bookworm)file 1:5.35-3 (bookworm)
file_projectfile
file_projectfile>= 0 < 1:5.35-31:5.35-3
file_projectfile>= 0 < 1:5.35-31:5.35-3
file_projectfile>= 0 < 1:5.35-31:5.35-3
file_projectfile>= 0 < 1:5.35-31:5.35-3
opensuseleap
opensuseleap

CVSS provenance

nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
osv4.4MEDIUM