CVE-2019-8905: Medium severity Debian Debian Linux vulnerability
Published Feb 18, 2019
·Updated
docorenote in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to fileprintable, a different vulnerability than CVE-2018-10360.
Affected Software
8 affected componentsFixes available
Debian Debian Linux=8.0
File Project File=5.35
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
openSUSE Leap=15.0
openSUSE Leap=42.3
debian/file
1:5.39-3+deb11u11:5.44-31:5.46-5
Remediation
Event History
Feb 18, 2019
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:32 PM
Description
Feb 23, 2026
Data Sourced
via Ubuntu·05:27 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·05:28 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2019-8905?
CVE-2019-8905 is a vulnerability related to a stack-based buffer over-read in do_core_note function in libmagic.a in file 5.35.
2
What software versions are affected by CVE-2019-8905?
CVE-2019-8905 affects file version 5.35 on Debian Linux 8.0, Ubuntu Linux 16.04, Ubuntu Linux 18.04, Ubuntu Linux 18.10, openSUSE Leap 15.0, and openSUSE Leap 42.3.
3
What is the severity of CVE-2019-8905?
The severity of CVE-2019-8905 is medium with a CVSS score of 4.4.
4
How can I fix CVE-2019-8905 on Ubuntu Linux?
To fix CVE-2019-8905 on Ubuntu Linux, update the file package to version 1:5.35-3.
5
Where can I find more information about CVE-2019-8905?
You can find more information about CVE-2019-8905 at the following references: [1] [2] [3]