Out-of-bounds read in file - CVE-2022-48554

 

Out-of-bounds read in file - CVE-2022-48554

Published: September 5, 2023


Vulnerability identifier: #VU80421
CSH Severity: Low
CVSS v4 BT: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-48554
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition within the file_copystr() function in funcs.c. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger an out-of-bounds read error and crash the application.


Affected software

file
Isolation Segment
VMware Tanzu Application Service for VMs
Submariner
Multicluster GlobalHub
Service Interconnect
Ansible Automation Platform
Red Hat Advanced Cluster Management for Kubernetes
Custom Metrics Autoscaler Operator for Red Hat OpenShift
IBM Cloud Transformation Advisor
Red Hat OpenShift Dev Spaces
App Connect Enterprise Certified Container
Red Hat Migration Toolkit for Applications
Red Hat OpenStack
Juniper Cloud Native Router
Amazon Linux AMI
Gentoo Linux
Debian Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
watchOS
macOS
iPadOS
tvOS
Apple iOS
openEuler
Ubuntu
Voice Gateway
Cloud Pak for Network Automation
IBM Business Automation Manager Open Editions
IBM Cloud Pak for Watson AIOps
Cognos Dashboards on Cloud Pak for Data
Robotic Process Automation for Cloud Pak
OpenShift API for Data Protection (OADP)
Network Observability plugin for the Openshift Console
OpenShift Service Mesh
Multicluster Engine for Kubernetes
VMware Tanzu Operations Manager
OpenShift Virtualization
OpenShift Container Platform for Windows Containers
Red Hat OpenShift Container Platform
file (Debian package)
file-help
file
file-debuginfo
file-libs
file-devel
file-debugsource
python2-magic
python3-magic
file (Red Hat package)
libmagic1 (Ubuntu package)
file (Ubuntu package)
sys-apps/file
Junos cRPD

How to mitigate CVE-2022-48554

Install updates from vendor's website.

file - update to 5.43
Voice Gateway - update to 1.0.8.12
Cloud Pak for Network Automation - update to 2.7.4
IBM Business Automation Manager Open Editions - update to 9.1.1
watchOS - update to 10.4
macOS - update to 14.4 23E214
iPadOS - update to 17.4 21E217
tvOS - update to 17.4
Apple iOS - update to 17.4 21E217
Submariner - update to 0.18.5
Multicluster GlobalHub - update to 1.2.1
OpenShift API for Data Protection (OADP) - update to 1.3.2
Service Interconnect - update to 1.5.4
Network Observability plugin for the Openshift Console - update to 1.6.0
Ansible Automation Platform - update to 2.4
OpenShift Service Mesh - addressed in versions 2.4.8, 2.5.2
Multicluster Engine for Kubernetes - addressed in versions 2.5.8, 2.6.4, 2.6.7, 2.7.2, 2.7.4
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.10.5, 2.10.8, 2.11.4, 2.11.7, 2.12.0, 2.12.1, 2.12.3
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-394
VMware Tanzu Operations Manager - update to 3.0.16
IBM Cloud Transformation Advisor - update to 3.10.0
Red Hat OpenShift Dev Spaces - addressed in versions 3.16.0, 3.17.0
IBM Cloud Pak for Watson AIOps - update to 4.7.0
OpenShift Virtualization - update to 4.14.6
Red Hat OpenShift Container Platform - addressed in versions 4.16.15, 4.16.44, 4.17.0
App Connect Enterprise Certified Container - addressed in versions 5.0.18, 11.6.0
Cognos Dashboards on Cloud Pak for Data - update to 5.1.1
file (Debian package) - update to 1:5.39-3+deb11u1
file-help - update to 5.39-7
file - update to 5.39-7
file-debuginfo - update to 5.39-7
file-libs - update to 5.39-7
file-devel - update to 5.39-7
file - update to 5.39-7
file-debugsource - update to 5.39-7
python2-magic - update to 5.39-7
python3-magic - update to 5.39-7
file (Red Hat package) - update to 5.39-16.el9
libmagic1 (Ubuntu package) - update to 1:5.41-3ubuntu0.1
file (Ubuntu package) - update to 1:5.41-3ubuntu0.1
sys-apps/file - update to 5.42
Red Hat Migration Toolkit for Applications - addressed in versions 6.2.3, 7.0.3
OpenShift Container Platform for Windows Containers - addressed in versions 8.1.3, 10.15.3
Red Hat OpenStack - update to 17.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.10, 23.0.11
Junos cRPD - update to 23.4R1
Juniper Cloud Native Router - update to 23.4R1

External References

Related Security Bulletins