Stack-based Buffer Over-read in File Utility from Vendor
CVE-2019-8905

4.4MEDIUM

Key Information:

Vendor
Debian
Vendor
CVE Published:
18 February 2019

Summary

A stack-based buffer over-read has been identified in the File utility version 5.35 within the function do_core_note in readelf.c. This flaw can lead to unexpected behavior during file processing, potentially allowing attackers to exploit this vulnerability in a way that could result in information disclosure or disruption of services. It is crucial for users to update their installations to address this security concern and enhance the resilience of their systems.

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.