Integer underflow in the file_printf function in the "file" program before 4.20 allows user-assisted attackers to execute arbitrary code via a file that triggers a heap-based buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx File | — | Apply OS X security update 2007-005 | Dec 16, 2011 | Mar 20, 2007 |
| Debian | — | Upgrade file | Jul 30, 2024 | Mar 20, 2007 |
| Freebsd | — | Upgrade fileUpgrade FreeBSD | Dec 10, 2025 | May 23, 2007 |
| Gentoo Linux | — | Upgrade sys-apps/file.Upgrade app-emulation/emul-linux-x86-baselibs.Upgrade app-forensics/sleuthkit. | Oct 30, 2017 | Mar 20, 2007 |
| Suse | — | Upgrade libmagic1Upgrade fileUpgrade file-x86Upgrade file-develUpgrade file-magicUpgrade file-32bit | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libmagic1 | Nov 8, 2024 | Mar 20, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub