File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: "File" is the name of an Open Source project.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade file-libsUpgrade file-develUpgrade fileUpgrade python3-file-magic | May 8, 2024 | Aug 22, 2023 |
| Alpine Linux | — | Upgrade file | Mar 21, 2024 | Aug 22, 2023 |
| Amazon_linux_2023 | — | Upgrade fileUpgrade file-debugsourceUpgrade file-libs-debuginfoUpgrade file-staticUpgrade python3-file-magicUpgrade file-libsUpgrade file-develUpgrade file-debuginfo | Feb 17, 2025 | Jan 21, 2022 |
| Apple Osx File | — | Upgrade macOS to the latest version | Jun 25, 2026 | Mar 7, 2024 |
| Debian | — | Upgrade file | Sep 6, 2023 | Aug 22, 2023 |
| Gentoo Linux | — | Upgrade sys-apps/file. | Sep 23, 2024 | Aug 22, 2023 |
| Huawei Euleros 2_0_sp10 | — | Upgrade fileUpgrade python3-magicUpgrade file-libs | Jan 10, 2024 | Aug 22, 2023 |
| Huawei Euleros 2_0_sp11 | — | Upgrade python3-magicUpgrade file-libsUpgrade file | Jan 10, 2024 | Aug 22, 2023 |
| Oracle_linux | — | Upgrade file-libsUpgrade file-develUpgrade python3-file-magicUpgrade file | May 7, 2024 | Jan 21, 2022 |
| Redhat_linux | — | Upgrade file-debugsourceUpgrade file-libs-debuginfoUpgrade fileUpgrade python3-file-magicNo solution existsUpgrade file-develUpgrade file-debuginfoUpgrade file-libs | May 1, 2024 | Aug 22, 2023 |
| Rocky_linux | — | Upgrade file-debuginfoUpgrade file-libsUpgrade fileUpgrade file-develUpgrade file-debugsourceUpgrade file-libs-debuginfo | May 13, 2024 | Aug 22, 2023 |
| Ubuntu | — | Upgrade fileUpgrade libmagic1 | Sep 18, 2023 | Aug 22, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Aug 22, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub