File Local Stack Overflow Code Execution Vulnerability

BID:7008

Info

File Local Stack Overflow Code Execution Vulnerability

Bugtraq ID: 7008
Class: Boundary Condition Error
CVE: CVE-2003-0102
Remote: No
Local: Yes
Published: Mar 04 2003 12:00AM
Updated: Jul 11 2009 08:06PM
Credit: Discovery credited to an anonymous researcher.
Vulnerable: NetBSD NetBSD 1.6
NetBSD NetBSD 1.5.3
NetBSD NetBSD 1.5.2
NetBSD NetBSD 1.5.1
NetBSD NetBSD 1.5
file file 3.40
file file 3.39
+ FreeBSD FreeBSD 5.0
+ MandrakeSoft Corporate Server 2.1
+ Mandriva Linux Mandrake 9.0
+ Redhat Linux for iSeries 7.1
+ Redhat Linux for pSeries 7.1
+ Sun Cobalt Qube 3
+ Sun Cobalt RaQ 4
+ Sun Cobalt RaQ 550
+ Sun Cobalt RaQ XTR
+ Sun Linux 5.0.6
+ Sun LX50
file file 3.37
+ Mandriva Linux Mandrake 8.2 ppc
+ Mandriva Linux Mandrake 8.2
+ Redhat Linux 8.0 i386
+ Redhat Linux 8.0
+ Redhat Linux 7.3 i386
+ Redhat Linux 7.3
file file 3.36
+ Mandriva Linux Mandrake 8.1 ia64
+ Mandriva Linux Mandrake 8.1
file file 3.35
+ Redhat Linux 7.2 ia64
+ Redhat Linux 7.2 i686
+ Redhat Linux 7.2 i586
+ Redhat Linux 7.2 i386
+ Redhat Linux 7.2
+ Trustix Secure Linux 1.5
file file 3.34
+ Mandriva Linux Mandrake 8.0 ppc
+ Mandriva Linux Mandrake 8.0
file file 3.33
+ Redhat Linux 7.1 i686
+ Redhat Linux 7.1 i586
+ Redhat Linux 7.1 i386
+ Redhat Linux 7.1
file file 3.32
+ MandrakeSoft Single Network Firewall 7.2
+ Mandriva Linux Mandrake 7.2
+ Trustix Secure Linux 1.2
+ Trustix Secure Linux 1.1
file file 3.30
+ Immunix Immunix OS 7+
+ Redhat Linux 7.0 i686
+ Redhat Linux 7.0 i386
+ Redhat Linux 7.0
file file 3.28
+ Caldera OpenLinux Server 3.1.1
+ Caldera OpenLinux Server 3.1
+ Caldera OpenLinux Workstation 3.1.1
+ Caldera OpenLinux Workstation 3.1
+ Redhat Linux 6.2 i386
+ Redhat Linux 6.2
Not Vulnerable: file file 3.41
+ Trustix Secure Linux 1.5
+ Trustix Secure Linux 1.2
+ Trustix Secure Linux 1.1

Discussion

File Local Stack Overflow Code Execution Vulnerability

It has been reported that a stack overflow exists in the file program. Although details of this issue are currently unavailable, it is likely that this issue could be exploited to execute code as the user invoking file.

Exploit / POC

File Local Stack Overflow Code Execution Vulnerability

Exploit code has been released.

Solution / Fix

File Local Stack Overflow Code Execution Vulnerability

Solution:
Sun has updated its advisory (Sun Alert ID: 56040) and has included fixes to address this issue for Sun Linux 5.0.6. Fixes for other affected Sun products are pending release.

Immunix has released a security advisory (IMNX-2003-7+-012-01) and fixes for this issue. Users are advised to upgrade as soon as possible.

SuSE has released a security advisory (SuSE-SA:2003:017) which contains fixes for this issue. Users are advised to upgrade as soon as possible.

Gentoo Linux users running sys-apps/file may upgrade to file-3.41 with the following commands:

emerge sync
emerge file
emerge clean

NetBSD Security Advisory 2003-003 has been released. Information on how to update vulnerable installations via CVS can be obtained from the attached advisory.

Trustix advisory TSL-2003-0006 contains fixes which address this issue. Please see the attached advisory for details on obtaining and applying fixes.

Fixes have been made available:


file file 3.28

file file 3.30

file file 3.32

file file 3.33

file file 3.34

file file 3.35

file file 3.36

file file 3.37

file file 3.39

file file 3.40

References

File Local Stack Overflow Code Execution Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report