CVE-2019-8904: High severity File Project File vulnerability
dobidnote in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to fileprintf and filevprintf.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-8904?
CVE-2019-8904 is a vulnerability in libmagic.a in file 5.35 that allows for a stack-based buffer over-read.
How severe is CVE-2019-8904?
CVE-2019-8904 has a severity rating of 8.8 (High).
What is the affected software?
The affected software includes file 5.35 on Ubuntu Linux 16.04, Ubuntu Linux 18.04, Ubuntu Linux 18.10, and Debian.
Is there a fix available for CVE-2019-8904?
Yes, the remedy for CVE-2019-8904 is to update file to version 1:5.35-3 on Ubuntu and to versions 1:5.35-4+deb10u2, 1:5.35-4+deb10u1, 1:5.39-3+deb11u1, 1:5.44-3, or 1:5.45-2 on Debian.
Where can I find more information about CVE-2019-8904?
More information about CVE-2019-8904 can be found at the following references: http://www.securityfocus.com/bid/107130, https://bugs.astron.com/view.php?id=62, https://usn.ubuntu.com/3911-1/