-Infinity
0

Vendor Risk Score

See how file compares to other vendors in security performance

View Risk Score →

Software

Severity
4.6
Buffer Overflow
AV:L/AC:L/Au:N/C:P/I:P/A:P

Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user running file, possibly via a large entity size value in an ELF header (elfhdr.eshentsize).

First published (updated )

Hi Erik,

On 2025-08-17 16:09:37 +0200, Erik Auerswald wrote: On Sun, Aug 17, 2025 at 03:09:58AM +0200, Vincent Lefevre wrote: I see this more than a feature, at least in the case the output is done to a terminal. As a general rule, programs are expected to sanitize output data in such as a case. I'd expect most programs to not change the filename printed in their output. POSIX does not even expect "ls" to sanitize its output without "-q", but it does allow it[0]. Probably because of historical behavior. But nowadays, one should be stricter concerning security. Two more example programs that do not sanitize filenames in their output would be "file", at least version "5.41", file 5.46 sanitizes filenames:

$ file --version file-5.46 magic file from /etc/magic:/usr/share/misc/magic $ file file file\033[H\033[c\012\010: empty and "dash", at least the version[1] included in Ubuntu GNU/Linux 22.04.5 LTS. Ditto for dash 0.5.12-12 (with "chmod 0 file" then "dash file"). I'd expect that you can find many more examples. Getting every program changed to follow your expectation seems like a Sisyphean task to me. This is less an issue for dash, because the user will probably not run a script that he hasn't written or controled in some other way. I am quite sure that there are many more such programs. GNU ed too. It outputs the file name unsanitized in its error message saying that control characters 1-31 are not allowed in file name!

-- Vincent Lefèvre <vincent () vinc17 net> - Web: <https://www.vinc17.net/> 100% accessible validated (X)HTML - Blog: <https://www.vinc17.net/blog/> Work: CR INRIA - computer arithmetic / Pascaline project (LIP, ENS-Lyon)

Severity
10
Buffer Overflow
AV:N/AC:L/Au:N/C:C/I:C/A:C

Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF file.

First published (updated )
Severity
5.1
Integer Overflow
AV:N/AC:H/Au:N/C:P/I:P/A:P

Integer overflow in the "file" program 4.20, when running on 32-bit systems, as used in products including The Sleuth Kit, might allow user-assisted attackers to execute arbitrary code via a large file that triggers an overflow that bypasses an assert() statement. NOTE: this issue is due to an incorrect patch for CVE-2007-1536.

First published (updated )
Severity
9.3
Buffer Overflow
AV:N/AC:M/Au:N/C:C/I:C/A:C

Integer underflow in the fileprintf function in the "file" program before 4.20 allows user-assisted attackers to execute arbitrary code via a file that triggers a heap-based buffer overflow.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203