SB2019031820 - Stack out-of-bounds read in file (Alpine package)
Published: March 18, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Stack out-of-bounds read (CVE-ID: CVE-2019-8904)
The vulnerability allows a remote attacker to obtain potentially sensitive information or perform a denial of service (DoS) attack.
The vulnerability exists due to stack-based buffer over-read in the do_core_note function, as defined in the readelf.c source code file. A remote attacker can trick the victim into executing a file that submits malicious input to the targeted system with the file command, trigger memory corruption and gain access to arbitrary data or perform a denial of service attack.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=6d181d271ac91ff2d8302855abd03d6a2be5dc27
- https://git.alpinelinux.org/aports/commit/?id=9e177e38d94223a06ed62c20ac5ba1e4c0fecf1c
- https://git.alpinelinux.org/aports/commit/?id=dc538f4f70353a02d01dac905fb662412befffbe
- https://git.alpinelinux.org/aports/commit/?id=33bd61f256dd1826d6a7df5ebb8a9e2fc1125ce1
- https://git.alpinelinux.org/aports/commit/?id=867138742023dde9397648e41743a9173432a7b2
- https://git.alpinelinux.org/aports/commit/?id=8b903beb77c68c97ba0aa36e58b6750edc06ca78
- https://git.alpinelinux.org/aports/commit/?id=27d87cf2365bff16337278a4e93a16df7f33f2e4