ALPINE-CVE-2019-8904 PUBLISHED CVSS 8.800000190734863 HIGH

do_bid_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printf and file_vprintf.

Risk Scores

CVSS v3.0
8.800000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Alpine:v3.20file5.35-r0, 0, 4.26-r1
Alpine:v3.11file0, 4.26-r1, 5.00-r0
Alpine:v3.17file0, 5.35-r0, 5.33-r0
Alpine:v3.13file0, 4.26-r1, 5.00-r0
Alpine:v3.23file0, 5.35-r0, 5.33-r0
Alpine:v3.10file4.26-r1, 0, 5.35-r0
Alpine:v3.21file5.35-r0, 0, 4.26-r1
Alpine:v3.18file5.35-r0, 0, 4.26-r1
Alpine:v3.14file4.26-r1, 5.00-r0, 5.01-r0
Alpine:v3.15file5.16-r0, 5.33-r0, 5.32-r0
Alpine:v3.12file5.31-r1, 5.31-r0, 5.30-r0
Alpine:v3.9file5.35-r0, 0, 4.26-r1
Alpine:v3.22file5.35-r0, 0, 4.26-r1
Alpine:v3.16file0, 4.26-r1, 5.00-r0
Alpine:v3.19file0, 5.35-r0, 5.33-r0

Timeline

References

Open in Interactive Console →