cbcvebase.

Debian File vulnerabilities

41 known vulnerabilities affecting debian/file.

Total CVEs
41
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH8MEDIUM25LOW4

Vulnerabilities

Page 1 of 3
CVE-2004-1304P3CRITICALCVSS 10.0PoCfixed in file 4.12 (bookworm)2004
CVE-2004-1304 [CRITICAL] CVE-2004-1304: file - Stack-based buffer overflow in the ELF header parsing code in file before 4.12 a... Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF file. Scope: local bookworm: resolved (fixed in 4.12) bullseye: resolved (fixed in 4.12) forky: resolved (fixed in 4.12) sid: resolved (fixed in 4.12) trixie: resolved (fixed in 4.12)
debian
CVE-2007-1536P3HIGHCVSS 9.3PoCfixed in file 4.20-1 (bookworm)2007
CVE-2007-1536 [CRITICAL] CVE-2007-1536: file - Integer underflow in the file_printf function in the "file" program before 4.20 ... Integer underflow in the file_printf function in the "file" program before 4.20 allows user-assisted attackers to execute arbitrary code via a file that triggers a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 4.20-1) bullseye: resolved (fixed in 4.20-1) forky: resolved (fixed in 4.20-1) sid: resolved (fixed in 4.20-1) trixie: resolved (fixed
debian
CVE-2003-1092P4HIGHCVSS 7.5PoCfixed in file 3.4.1 (bookworm)2003
CVE-2003-1092 [HIGH] CVE-2003-1092: file - Unknown vulnerability in the "Automatic File Content Type Recognition (AFCTR) To... Unknown vulnerability in the "Automatic File Content Type Recognition (AFCTR) Tool version of the file package before 3.41, related to "a memory allocation problem," has unknown impact. Scope: local bookworm: resolved (fixed in 3.4.1) bullseye: resolved (fixed in 3.4.1) forky: resolved (fixed in 3.4.1) sid: resolved (fixed in 3.4.1) trixie: resolved (fixed in 3.4.1)
debian
CVE-2009-0948P3CRITICALCVSS 9.8fixed in file 5.02-1 (bookworm)2009
CVE-2009-0948 [CRITICAL] CVE-2009-0948: file - Multiple buffer overflows in the (1) cdf_read_sat, (2) cdf_read_long_sector_chai... Multiple buffer overflows in the (1) cdf_read_sat, (2) cdf_read_long_sector_chain, and (3) cdf_read_ssat function in file before 5.02. Scope: local bookworm: resolved (fixed in 5.02-1) bullseye: resolved (fixed in 5.02-1) forky: resolved (fixed in 5.02-1) sid: resolved (fixed in 5.02-1) trixie: resolved (fixed in 5.02-1)
debian
CVE-2009-0947P3CRITICALCVSS 9.8fixed in file 5.02-1 (bookworm)2009
CVE-2009-0947 [CRITICAL] CVE-2009-0947: file - Multiple integer overflows in the (1) cdf_read_property_info and (2) cdf_read_sa... Multiple integer overflows in the (1) cdf_read_property_info and (2) cdf_read_sat functions in file before 5.02. Scope: local bookworm: resolved (fixed in 5.02-1) bullseye: resolved (fixed in 5.02-1) forky: resolved (fixed in 5.02-1) sid: resolved (fixed in 5.02-1) trixie: resolved (fixed in 5.02-1)
debian
CVE-2019-18218P3HIGHCVSS 7.8fixed in file 1:5.37-6 (bookworm)2019
CVE-2019-18218 [HIGH] CVE-2019-18218: file - cdf_read_property_info in cdf.c in file through 5.37 does not restrict the numbe... cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write). Scope: local bookworm: resolved (fixed in 1:5.37-6) bullseye: resolved (fixed in 1:5.37-6) forky: resolved (fixed in 1:5.37-6) sid: resolved (fixed in 1:5.37-6) trixie: resolved (fixed in 1:5.3
debian
CVE-2019-8904P3HIGHCVSS 8.8fixed in file 1:5.35-3 (bookworm)2019
CVE-2019-8904 [HIGH] CVE-2019-8904: file - do_bid_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer ove... do_bid_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printf and file_vprintf. Scope: local bookworm: resolved (fixed in 1:5.35-3) bullseye: resolved (fixed in 1:5.35-3) forky: resolved (fixed in 1:5.35-3) sid: resolved (fixed in 1:5.35-3) trixie: resolved (fixed in 1:5.35-3)
debian
CVE-2014-0207P3MEDIUMCVSS 6.5fixed in file 1:5.19-1 (bookworm)2014
CVE-2014-0207 [MEDIUM] CVE-2014-0207: file - The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the ... The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted CDF file. Scope: local bookworm: resolved (fixed in 1:5.19-1) bullseye: resolved (fixed in 1:5.19-1) forky: resolved (
debian
CVE-2014-9653P3HIGHCVSS 7.5fixed in file 1:5.22+15-1 (bookworm)2014
CVE-2014-9653 [HIGH] CVE-2014-9653: file - readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5... readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory access) or possibly have unspecified other impact via a crafted ELF file.
debian
CVE-2015-8865P3HIGHCVSS 7.3fixed in file 1:5.24-1 (bookworm)2015
CVE-2015-8865 [HIGH] CVE-2015-8865: file - The file_check_mem function in funcs.c in file before 5.23, as used in the Filei... The file_check_mem function in funcs.c in file before 5.23, as used in the Fileinfo component in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5, mishandles continuation-level jumps, which allows context-dependent attackers to cause a denial of service (buffer overflow and application crash) or possibly execute arbitrary code via a crafted magic file. Scope:
debian
CVE-2019-8907P3HIGHCVSS 8.8fixed in file 1:5.35-3 (bookworm)2019
CVE-2019-8907 [HIGH] CVE-2019-8907: file - do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to ... do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified other impact. Scope: local bookworm: resolved (fixed in 1:5.35-3) bullseye: resolved (fixed in 1:5.35-3) forky: resolved (fixed in 1:5.35-3) sid: resolved (fixed in 1:5.35-3) trixie: resolved (fixe
debian
CVE-2003-0102P4MEDIUMCVSS 4.6PoCfixed in file 3.40-1.1 (bookworm)2003
CVE-2003-0102 [MEDIUM] CVE-2003-0102: file - Buffer overflow in tryelf() in readelf.c of the file command allows attackers to... Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user running file, possibly via a large entity size value in an ELF header (elfhdr.e_shentsize). Scope: local bookworm: resolved (fixed in 3.40-1.1) bullseye: resolved (fixed in 3.40-1.1) forky: resolved (fixed in 3.40-1.1) sid: resolved (fixed in 3.40-1.1) tr
debian
CVE-2014-3480P4MEDIUMCVSS 6.5fixed in file 1:5.19-1 (bookworm)2014
CVE-2014-3480 [MEDIUM] CVE-2014-3480: file - The cdf_count_chain function in cdf.c in file before 5.19, as used in the Filein... The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. Scope: local bookworm: resolved (fixed in 1:5.19-1) bullseye: resolved (fixed in 1:
debian
CVE-2014-0237P4MEDIUMCVSS 5.0fixed in file 1:5.19-1 (bookworm)2014
CVE-2014-0237 [MEDIUM] CVE-2014-0237: file - The cdf_unpack_summary_info function in cdf.c in the Fileinfo component in PHP b... The cdf_unpack_summary_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (performance degradation) by triggering many file_printf calls. Scope: local bookworm: resolved (fixed in 1:5.19-1) bullseye: resolved (fixed in 1:5.19-1) forky: resolved (fixed in 1:5.19-1) sid: resol
debian
CVE-2014-0238P4MEDIUMCVSS 5.0fixed in file 1:5.19-1 (bookworm)2014
CVE-2014-0238 [MEDIUM] CVE-2014-0238: file - The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP be... The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (infinite loop or out-of-bounds memory access) via a vector that (1) has zero length or (2) is too long. Scope: local bookworm: resolved (fixed in 1:5.19-1) bullseye: resolved (fixed in 1:5.19-1) forky:
debian
CVE-2014-3478P4MEDIUMCVSS 6.5fixed in file 1:5.19-1 (bookworm)2014
CVE-2014-3478 [MEDIUM] CVE-2014-3478: file - Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as ... Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (application crash) via a crafted Pascal string in a FILE_PSTRING conversion. Scope: local bookworm: resolved (fixed in 1:5.19-1) bullseye: resolved (fixed in 1:
debian
CVE-2009-3930P4CRITICALCVSS 9.3fixed in file 5.03-1 (bookworm)2009
CVE-2009-3930 [CRITICAL] CVE-2009-3930: file - Multiple integer overflows in Christos Zoulas file before 5.02 allow user-assist... Multiple integer overflows in Christos Zoulas file before 5.02 allow user-assisted remote attackers to have an unspecified impact via a malformed compound document (aka cdf) file that triggers a buffer overflow. Scope: local bookworm: resolved (fixed in 5.03-1) bullseye: resolved (fixed in 5.03-1) forky: resolved (fixed in 5.03-1) sid: resolved (fixed in 5.03-1) trix
debian
CVE-2014-0236P4HIGHCVSS 7.5fixed in file 1:5.19-1 (bookworm)2014
CVE-2014-0236 [HIGH] CVE-2014-0236: file - file before 5.18, as used in the Fileinfo component in PHP before 5.6.0, allows ... file before 5.18, as used in the Fileinfo component in PHP before 5.6.0, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a zero root_storage value in a CDF file, related to cdf.c and readcdf.c. Scope: local bookworm: resolved (fixed in 1:5.19-1) bullseye: resolved (fixed in 1:5.19-1) forky: resolved (fixed in 1:5.
debian
CVE-2014-3587P4MEDIUMCVSS 6.5fixed in file 1:5.19-2 (bookworm)2014
CVE-2014-3587 [MEDIUM] CVE-2014-3587: file - Integer overflow in the cdf_read_property_info function in cdf.c in file through... Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1571. Scope: local bookworm: reso
debian
CVE-2014-3538P4MEDIUMCVSS 5.0fixed in file 1:5.19-1 (bookworm)2014
CVE-2014-3538 [MEDIUM] CVE-2014-3538: file - file before 5.19 does not properly restrict the amount of data read during a reg... file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7345. Scope: local bookworm: resolved (fixed in 1
debian
Debian File vulnerabilities | cvebase