#VU13453 Out-of-bounds read in file - CVE-2018-10360
Published: June 23, 2018 / Updated: June 25, 2018
file
Ian F. Darwin
Description
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists in the do_core_note function in readelf.c in libmagic.a due to an error when processing malicious input. A remote attacker can send a specially crafted crafted ELF file, trigger out-of-bounds read and cause the service to crash.