Back

HIGH

file: heap-based buffer overflow in cdf_read_property_info in cdf.c

Published Oct 21, 2019

Description

cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).

Affected products

Remediation

Red Hat statement

This issue affects the `file` package as shipped with Red Hat Enterprise Linux 8. However, this flaw has been rated as having a security impact of Moderate because it is only exploitable if the 32bit version is used, for example when an application uses the 32bit version of libmagic.so.

Metrics

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 21, 2019
Updated Aug 5, 2024
Reserved Oct 21, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 26, 2019