Heap-based buffer overflow in file - CVE-2019-18218

 

Heap-based buffer overflow in file - CVE-2019-18218

Published: October 27, 2019


Vulnerability identifier: #VU22303
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-18218
CWE-ID: CWE-122
Exploitation vector: Local access
Exploit availability: No public exploit available
Affected software:
file
Amazon Linux AMI
Arch Linux
Gentoo Linux
HPE Helion Openstack
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Opensuse
Fedora
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Cloud Pak for Security (CP4S)
Ansible Automation Platform
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Red Hat OpenStack
file (Alpine package)
file (Ubuntu package)
file (Debian package)
file-devel
python-magic
libmagic1-debuginfo
libmagic1-debuginfo-32bit
libmagic1
libmagic1-32bit
file-magic
file-debugsource
file-debuginfo
file
file (Red Hat package)
php72
php73
Red Hat OpenShift Serverless
OpenShift Virtualization

Detailed vulnerability description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error within the cdf_read_property_info() function in cdf.c in file due to improper restrictions of the number of CDF_VECTOR elements. A local user can place a specially crafted CDF (Composite Document File) file on the system, trick the victim into reading it with the affected software, trigger heap-based buffer overflow (4-byte out-of-bounds write) and execute arbitrary code on the target system with elevated privileges.


How to mitigate CVE-2019-18218

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Sources