Out-of-bounds read in file - CVE-2019-8906

 

Out-of-bounds read in file - CVE-2019-8906

Published: February 21, 2019


Vulnerability identifier: #VU17823
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-8906
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information or perform a denial of service (DoS) attack.

The vulnerability exists due to out-of-bounds read in the do_core_note function. A remote attacker can trick the victim into executing a file that submits malicious input to the targeted system with the file command, trigger memory corruption and gain access to arbitrary data or perform a denial of service attack.


Affected software

file
Arch Linux
Amazon Linux AMI
Slackware Linux
Opensuse
Fedora
file (Ubuntu package)
file (Alpine package)
file
Dell EMC Container Storage Modules

How to mitigate CVE-2019-8906

Update to version 5.36.

file - update to 5.36
file (Ubuntu package) - addressed in versions 1:5.25-2ubuntu1.2, 1:5.32-2ubuntu0.2, 1:5.34-2ubuntu0.1
file (Alpine package) - update to 5.32-r1
Dell EMC Container Storage Modules - update to 1.7.0
file - addressed in versions 5.33-10.fc28, 5.34-12.fc29

External References

Related Security Bulletins