CVE-2019-8907: High severity File Project File vulnerability
docorenote in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified other impact.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-8907?
CVE-2019-8907 is a vulnerability in libmagic.a in file 5.35 that allows remote attackers to cause a denial of service or possibly have unspecified other impact.
What is the severity of CVE-2019-8907?
The severity of CVE-2019-8907 is high with a CVSS score of 8.8.
How does CVE-2019-8907 affect the affected software?
CVE-2019-8907 affects file version 5.35, Debian Linux 8.0, openSUSE Leap 15.0, and Ubuntu Linux 16.04, 18.04, and 18.10.
How do I fix CVE-2019-8907 on Ubuntu Linux?
To fix CVE-2019-8907 on Ubuntu Linux, you can update the file package to version 1:5.35-3.
Where can I find more information about CVE-2019-8907?
You can find more information about CVE-2019-8907 from the OpenSUSE security announcement, Debian security announcement, and the bug report.