Vulnerability Description
do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.
CVSS Score
4.4
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| File Project | File | 5.35 |
| Canonical | Ubuntu Linux | 16.04 |
| Opensuse | Leap | 15.0 |
| Apple | Iphone Os | < 12.2 |
| Apple | Mac Os X | < 10.14.4 |
| Apple | Tvos | < 12.2 |
| Apple | Watchos | < 5.2 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00027.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00053.htmlMailing ListThird Party Advisory
- https://bugs.astron.com/view.php?id=64ExploitIssue TrackingThird Party Advisory
- https://github.com/file/file/commit/2858eaf99f6cc5aae129bcbf1e24ad160240185fPatchThird Party Advisory
- https://support.apple.com/kb/HT209599Third Party Advisory
- https://support.apple.com/kb/HT209600Third Party Advisory
- https://support.apple.com/kb/HT209601Third Party Advisory
- https://support.apple.com/kb/HT209602Third Party Advisory
- https://usn.ubuntu.com/3911-1/Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00027.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00053.htmlMailing ListThird Party Advisory
- https://bugs.astron.com/view.php?id=64ExploitIssue TrackingThird Party Advisory
- https://github.com/file/file/commit/2858eaf99f6cc5aae129bcbf1e24ad160240185fPatchThird Party Advisory
- https://support.apple.com/kb/HT209599Third Party Advisory
- https://support.apple.com/kb/HT209600Third Party Advisory
FAQ
What is CVE-2019-8906?
CVE-2019-8906 is a vulnerability with a CVSS score of 4.4 (MEDIUM). do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.
How severe is CVE-2019-8906?
CVE-2019-8906 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-8906?
Check the references section above for vendor advisories and patch information. Affected products include: File Project File, Canonical Ubuntu Linux, Opensuse Leap, Apple Iphone Os, Apple Mac Os X.