file CDF File Parsing Multiple Buffer Overflow Vulnerabilities
BID:37074
Info
file CDF File Parsing Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 37074 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-3930 |
| Remote: | Yes |
| Local: | No |
| Published: | May 04 2009 12:00AM |
| Updated: | Nov 19 2009 08:35PM |
| Credit: | Drew Yao |
| Vulnerable: |
file file 5.01 file file 5.0 |
| Not Vulnerable: |
file file 5.02 |
Discussion
file CDF File Parsing Multiple Buffer Overflow Vulnerabilities
The 'file' command is prone to multiple buffer-overflow vulnerabilities because it fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Attackers can execute arbitrary code in the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Versions prior to 'file' 5.02 are vulnerable.
The 'file' command is prone to multiple buffer-overflow vulnerabilities because it fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Attackers can execute arbitrary code in the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Versions prior to 'file' 5.02 are vulnerable.
Exploit / POC
file CDF File Parsing Multiple Buffer Overflow Vulnerabilities
An attacker can exploit these issues by enticing an unsuspecting victim to open a malicious file using the affected 'file' command.
An attacker can exploit these issues by enticing an unsuspecting victim to open a malicious file using the affected 'file' command.
Solution / Fix
file CDF File Parsing Multiple Buffer Overflow Vulnerabilities
Solution:
Updates are available. Please see the references for details.
file file 5.0
file file 5.01
Solution:
Updates are available. Please see the references for details.
file file 5.0
-
file file-5.02.tar.gz
ftp://ftp.astron.com/pub/file/file-5.02.tar.gz
file file 5.01
-
file file-5.02.tar.gz
ftp://ftp.astron.com/pub/file/file-5.02.tar.gz
References
file CDF File Parsing Multiple Buffer Overflow Vulnerabilities
References:
References:
- file Homepage (file)
- file-5.02 is now available (Christos Zoulas)