CVE-2019-8906
Summary
| CVE | CVE-2019-8906 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-02-18 17:29:00 UTC |
| Updated | 2021-12-09 19:44:00 UTC |
| Description | do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| About the security content of watchOS 5.2 - Apple Support |
CONFIRM |
support.apple.com |
Third Party Advisory |
| About the security content of iOS 12.2 - Apple Support |
CONFIRM |
support.apple.com |
Third Party Advisory |
| USN-3911-1: file vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| About the security content of tvOS 12.2 - Apple Support |
CONFIRM |
support.apple.com |
Third Party Advisory |
| [security-announce] openSUSE-SU-2019:1197-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
Mailing List, Third Party Advisory |
| About the security content of macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra - Apple Support |
CONFIRM |
support.apple.com |
Third Party Advisory |
| Avoid OOB read (found by ASAN reported by F. Alonso) · file/file@2858eaf · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| [security-announce] openSUSE-SU-2019:0345-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
Mailing List, Third Party Advisory |
| 0000064: ASAN: memcpy-param-overlap - MantisBT |
MISC |
bugs.astron.com |
Exploit, Issue Tracking, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500182 Alpine Linux Security Update for file
- 503921 Alpine Linux Security Update for file