RHSA-2024:2512: Low: file security update
Low: file security update
Other sources
The file command is used to identify a particular file according to the type of data the file contains. It can identify many different file types, including Executable and Linkable Format (ELF) binary files, system libraries, RPM packages, and different graphics formats.<br>Security Fix(es):<br><li> file: stack-based buffer over-read in filecopystr in funcs.c (CVE-2022-48554)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Additional Changes:<br>For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.4 Release Notes linked from the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2512?
The RHSA-2024:2512 vulnerability is classified as low severity.
How do I fix RHSA-2024:2512?
To fix RHSA-2024:2512, update the 'file' package to version 5.39-16.el9 or newer.
Which software is affected by RHSA-2024:2512?
The affected software for RHSA-2024:2512 includes various versions of Red Hat Enterprise Linux and CodeReady Linux Builder for multiple architectures.
What vulnerabilities does RHSA-2024:2512 address?
RHSA-2024:2512 addresses security issues related to the file command used for identifying file types.
Is there a recommended action for users affected by RHSA-2024:2512?
Affected users should update their systems to mitigate the vulnerabilities associated with RHSA-2024:2512.