CVE-2019-18218: Buffer Overflow
Published Oct 21, 2019
·Updated
cdfreadpropertyinfo in cdf.c in file through 5.37 does not restrict the number of CDFVECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
Affected Software
16 affected componentsFixes available
File Project File<=5.37
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
openSUSE Leap=15.1
NetApp Active Iq Unified Manager Linux>=7.3
Fedoraproject Fedora=29
Fedoraproject Fedora=30
Fedoraproject Fedora=31
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=19.04
Canonical Ubuntu Linux=19.10
debian/file
1:5.39-3+deb11u11:5.44-31:5.46-5
Remediation
Event History
Oct 21, 2019
CVE Published
via MITRE·04:41 AM
Data Sourced
via MITRE·04:41 AM
Description
Data Sourced
via NVD·05:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 21, 2026
Data Sourced
via Ubuntu·12:17 AM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·12:17 AM
DescriptionAffected Software
Data Sourced
via Launchpad·12:17 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-18218.
2
What is the severity of CVE-2019-18218?
The severity of CVE-2019-18218 is high.
3
How does CVE-2019-18218 affect the affected software?
CVE-2019-18218 affects the 'file' package in Ubuntu, Debian, openSUSE Leap, Netapp Active Iq Unified Manager, and Fedora.
4
How can I fix CVE-2019-18218?
To fix CVE-2019-18218, update the 'file' package to version 5.32-2ubuntu0.3 or later for Ubuntu, 5.35-4+deb10u2 or later for Debian, 15.1 or later for openSUSE Leap, 7.3 or later for Netapp Active Iq Unified Manager, and 29 or later for Fedora.
5
Where can I find more information about CVE-2019-18218?
You can find more information about CVE-2019-18218 at the following references: [LINK1], [LINK2], [LINK3].