Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF file.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade file | Jul 30, 2024 | Jan 10, 2005 |
| Gentoo Linux | — | Upgrade sys-apps/file. | Oct 30, 2017 | Jan 10, 2005 |
| Suse | — | Upgrade file-x86Upgrade fileUpgrade file-64bitUpgrade file-32bit | Dec 12, 2013 | Jan 10, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub