ALPINE-CVE-2019-8905 PUBLISHED CVSS 4.400000095367432 MEDIUM

do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360.

Risk Scores

CVSS v3.1
4.400000095367432
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

Affected Products

VendorProductVersions
Alpine:v3.8file5.32-r0, 5.31-r1, 5.31-r0
Alpine:v3.10file5.14-r0, 5.15-r0, 5.16-r0
Alpine:v3.19file5.07-r1, 5.35-r0, 5.33-r0
Alpine:v3.12file5.12-r0, 5.15-r0, 5.16-r0
Alpine:v3.16file5.14-r0, 5.35-r0, 5.33-r0
Alpine:v3.18file5.14-r0, 0, 4.26-r1
Alpine:v3.15file0, 4.26-r1, 5.00-r0
Alpine:v3.21file5.04-r0, 5.33-r0, 5.32-r0
Alpine:v3.7file5.11-r0, 5.12-r0, 5.14-r0
Alpine:v3.17file5.30-r0, 0, 4.26-r1
Alpine:v3.9file0, 5.30-r0, 5.31-r0
Alpine:v3.11file5.31-r1, 0, 4.26-r1
Alpine:v3.14file0, 5.35-r0, 5.33-r0
Alpine:v3.22file5.10-r0, 0, 4.26-r1
Alpine:v3.13file5.15-r0, 5.18-r0, 5.17-r0
Alpine:v3.20file5.33-r0, 5.35-r0, 5.33-r0
Alpine:v3.23file4.26-r1, 4.26-r1, 5.00-r0

Timeline

References

Open in Interactive Console →