Vulnerabilities
Vulnerable Software
File Project:  >> File  >> 5.29  Security Vulnerabilities
cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
CVSS Score
7.8
EPSS Score
0.002
Published
2019-10-21
An issue in file() was introduced in commit 9611f31313a93aa036389c5f3b15eea53510d4d1 (Oct 2016) lets an attacker overwrite a fixed 20 bytes stack buffer with a specially crafted .notes section in an ELF binary. This was fixed in commit 35c94dc6acc418f1ad7f6241a6680e5327495793 (Aug 2017).
CVSS Score
5.5
EPSS Score
0.001
Published
2017-09-11


Contact Us

Shodan ® - All rights reserved