This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor File Project First view 2014-12-17
Product File Last view 2019-10-21
Version Type Application
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:file_project:file:5.20:*:*:*:*:*:*:* 7
cpe:2.3:a:file_project:file:5.17:*:*:*:*:*:*:* 6
cpe:2.3:a:file_project:file:5.18:*:*:*:*:*:*:* 6
cpe:2.3:a:file_project:file:5.16:*:*:*:*:*:*:* 6
cpe:2.3:a:file_project:file:5.19:*:*:*:*:*:*:* 6
cpe:2.3:a:file_project:file:5.09:*:*:*:*:*:*:* 5
cpe:2.3:a:file_project:file:5.14:*:*:*:*:*:*:* 5
cpe:2.3:a:file_project:file:5.15:*:*:*:*:*:*:* 5
cpe:2.3:a:file_project:file:5.08:*:*:*:*:*:*:* 5
cpe:2.3:a:file_project:file:5.12:*:*:*:*:*:*:* 5
cpe:2.3:a:file_project:file:5.10:*:*:*:*:*:*:* 5
cpe:2.3:a:file_project:file:5.13:*:*:*:*:*:*:* 5
cpe:2.3:a:file_project:file:5.11:*:*:*:*:*:*:* 5
cpe:2.3:a:file_project:file:5.35:*:*:*:*:*:*:* 5
cpe:2.3:a:file_project:file:5.21:*:*:*:*:*:*:* 4
cpe:2.3:a:file_project:file:5.29:*:*:*:*:*:*:* 2
cpe:2.3:a:file_project:file:5.33:*:*:*:*:*:*:* 2

Related : CVE

  Date Alert Description
9.8 2019-10-21 CVE-2019-18218

cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).

8.8 2019-02-18 CVE-2019-8907

do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified other impact.

8.8 2019-02-18 CVE-2019-8906

do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.

8.8 2019-02-18 CVE-2019-8905

do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360.

8.8 2019-02-18 CVE-2019-8904

do_bid_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printf and file_vprintf.

6.5 2018-06-11 CVE-2018-10360

The do_core_note function in readelf.c in libmagic.a in file 5.33 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

5.5 2017-09-11 CVE-2017-1000249

An issue in file() was introduced in commit 9611f31313a93aa036389c5f3b15eea53510d4d1 (Oct 2016) lets an attacker overwrite a fixed 20 bytes stack buffer with a specially crafted .notes section in an ELF binary. This was fixed in commit 35c94dc6acc418f1ad7f6241a6680e5327495793 (Aug 2017).

7.5 2015-03-30 CVE-2014-9653

readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory access) or possibly have unspecified other impact via a crafted ELF file.

5 2015-03-30 CVE-2014-9652

The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file.

5 2015-01-21 CVE-2014-9621

The ELF parser in file 5.16 through 5.21 allows remote attackers to cause a denial of service via a long string.

5 2015-01-21 CVE-2014-9620

The ELF parser in file 5.08 through 5.21 allows remote attackers to cause a denial of service via a large number of notes.

5 2014-12-17 CVE-2014-8117

softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors.

5 2014-12-17 CVE-2014-8116

The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large number of (1) program or (2) section headers or (3) invalid capabilities.

CWE : Common Weakness Enumeration

%idName
30% (4) CWE-399 Resource Management Errors
30% (4) CWE-125 Out-of-bounds Read
15% (2) CWE-787 Out-of-bounds Write
15% (2) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
7% (1) CWE-20 Improper Input Validation

Nessus® Vulnerability Scanner

This CPE Product have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
id Description
2019-01-03 Name: The remote Fedora host is missing a security update.
File: fedora_2018-7cd597eebf.nasl - Type: ACT_GATHER_INFO
2018-08-17 Name: The remote PhotonOS host is missing multiple security updates.
File: PhotonOS_PHSA-2018-2_0-0080.nasl - Type: ACT_GATHER_INFO
2018-08-17 Name: The remote PhotonOS host is missing multiple security updates.
File: PhotonOS_PHSA-2018-1_0-0171.nasl - Type: ACT_GATHER_INFO
2018-08-02 Name: The remote Slackware host is missing a security update.
File: Slackware_SSA_2018-212-01.nasl - Type: ACT_GATHER_INFO
2018-06-29 Name: The remote Fedora host is missing a security update.
File: fedora_2018-b5de855e94.nasl - Type: ACT_GATHER_INFO
2018-06-25 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-201806-08.nasl - Type: ACT_GATHER_INFO
2018-01-15 Name: The remote Fedora host is missing a security update.
File: fedora_2017-6a10869603.nasl - Type: ACT_GATHER_INFO
2017-11-27 Name: The remote SUSE host is missing one or more security updates.
File: suse_SU-2017-3048-1.nasl - Type: ACT_GATHER_INFO
2017-11-27 Name: The remote openSUSE host is missing a security update.
File: openSUSE-2017-1298.nasl - Type: ACT_GATHER_INFO
2017-10-09 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-201710-02.nasl - Type: ACT_GATHER_INFO
2017-10-04 Name: The remote Amazon Linux AMI host is missing a security update.
File: ala_ALAS-2017-900.nasl - Type: ACT_GATHER_INFO
2017-09-12 Name: The remote Fedora host is missing a security update.
File: fedora_2017-bb4c07b01a.nasl - Type: ACT_GATHER_INFO
2017-09-08 Name: The remote Ubuntu host is missing one or more security-related patches.
File: ubuntu_USN-3412-1.nasl - Type: ACT_GATHER_INFO
2017-09-06 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-3965.nasl - Type: ACT_GATHER_INFO
2017-02-28 Name: The remote device is missing a vendor-supplied security patch.
File: f5_bigip_SOL16347.nasl - Type: ACT_GATHER_INFO
2017-01-18 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-201701-42.nasl - Type: ACT_GATHER_INFO
2016-08-29 Name: The remote SUSE host is missing one or more security updates.
File: suse_SU-2016-1638-1.nasl - Type: ACT_GATHER_INFO
2016-06-09 Name: The remote Scientific Linux host is missing one or more security updates.
File: sl_20160510_file_on_SL6_x.nasl - Type: ACT_GATHER_INFO
2016-05-17 Name: The remote CentOS host is missing one or more security updates.
File: centos_RHSA-2016-0760.nasl - Type: ACT_GATHER_INFO
2016-05-16 Name: The remote OracleVM host is missing one or more security updates.
File: oraclevm_OVMSA-2016-0050.nasl - Type: ACT_GATHER_INFO
2016-05-16 Name: The remote Oracle Linux host is missing one or more security updates.
File: oraclelinux_ELSA-2016-0760.nasl - Type: ACT_GATHER_INFO
2016-05-12 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2016-0760.nasl - Type: ACT_GATHER_INFO
2015-12-22 Name: The remote Scientific Linux host is missing one or more security updates.
File: sl_20151119_file_on_SL7_x.nasl - Type: ACT_GATHER_INFO
2015-12-02 Name: The remote CentOS host is missing one or more security updates.
File: centos_RHSA-2015-2155.nasl - Type: ACT_GATHER_INFO
2015-11-24 Name: The remote Oracle Linux host is missing one or more security updates.
File: oraclelinux_ELSA-2015-2155.nasl - Type: ACT_GATHER_INFO