Fedora 29: file FEDORA-2019-18036b898e

    Date09 Nov 2019
    CategoryFedora
    222
    Posted ByLinuxSecurity Advisories
    Fedora Large
    - fix heap-based buffer overflow in cdf_read_property_info() (CVE-2019-18218)
    --------------------------------------------------------------------------------
    Fedora Update Notification
    FEDORA-2019-18036b898e
    2019-11-10 01:06:02.434237
    --------------------------------------------------------------------------------
    
    Name        : file
    Product     : Fedora 29
    Version     : 5.34
    Release     : 15.fc29
    URL         : http://www.darwinsys.com/file/
    Summary     : A utility for determining file types
    Description :
    The file command is used to identify a particular file according to the
    type of data contained by the file.  File can identify many different
    file types, including ELF binaries, system libraries, RPM packages, and
    different graphics formats.
    
    --------------------------------------------------------------------------------
    Update Information:
    
    - fix heap-based buffer overflow in cdf_read_property_info() (CVE-2019-18218)
    --------------------------------------------------------------------------------
    ChangeLog:
    
    * Fri Oct 25 2019 Kamil Dudka  - 5.34-15
    - fix heap-based buffer overflow in cdf_read_property_info() (CVE-2019-18218)
    * Tue Jun 11 2019 Kamil Dudka  - 5.34-14
    - fix double free on read error (#1685217)
    * Fri Mar  1 2019 Kamil Dudka  - 5.34-13
    - improve support for Apple formats (#1679455)
    * Mon Feb 25 2019 Kamil Dudka  - 5.34-12
    - remote denial of service in do_core_note in readelf.c (CVE-2019-8907)
    - stack-based buffer over-read in do_core_note in readelf.c (CVE-2019-8905)
    - stack-based buffer over-read in do_bid_note in readelf.c (CVE-2019-8904)
    - out-of-bounds read in do_core_note in readelf.c (CVE-2019-8906)
    * Thu Jan 24 2019 Ondrej Dubaj  - 5.34-9
    - Added Linux PowerPC core offsets for Linux + fixed bug #1161911
    * Thu Jan 24 2019 Ondrej Dubaj  - 5.34-8
    - Fixed bug missidentifying netpbm files (#856092)
    * Tue Dec  4 2018 Ondrej Dubaj  - 5.34-7
    - Fixed bug misleading qcow2 v2 and v3 files (#1654349)
    - Changed bug report URL
    * Wed Nov 21 2018 Ondrej Dubaj  - 5.34-6
    - Fixed missidentifying locale files bug (#1527398)
    * Wed Nov 14 2018 Kamil Dudka  - 5.34-5
    - reintroduce the python2-magic subpackage needed by python2-bugzilla (#1649547)
    * Mon Nov 12 2018 Kamil Dudka  - 5.34-4
    - add magic for eBPF objects (#1648667)
    --------------------------------------------------------------------------------
    References:
    
      [ 1 ] Bug #1765273 - CVE-2019-18218 file: heap-based buffer overflow in cdf_read_property_info in cdf.c [fedora-all]
            https://bugzilla.redhat.com/show_bug.cgi?id=1765273
    --------------------------------------------------------------------------------
    
    This update can be installed with the "dnf" update program. Use
    su -c 'dnf upgrade --advisory FEDORA-2019-18036b898e' at the command
    line. For more information, refer to the dnf documentation available at
    http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
    
    All packages are signed with the Fedora Project GPG key. More details on the
    GPG keys used by the Fedora Project can be found at
    https://fedoraproject.org/keys
    --------------------------------------------------------------------------------
    _______________________________________________
    package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it.
    To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it.
    Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
    List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
    List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it.
    
    You are not authorised to post comments.

    Comments powered by CComment

    LinuxSecurity Poll

    What do you think of the articles on LinuxSecurity?

    No answer selected. Please try again.
    Please select either existing option or enter your own, however not both.
    Please select minimum 0 answer(s) and maximum 3 answer(s).
    /main-polls/24-what-do-you-think-of-the-quality-of-the-articles-on-linuxsecurity?task=poll.vote&format=json
    24
    radio
    [{"id":"87","title":"Excellent, don't change a thing!","votes":"39","type":"x","order":"1","pct":50.65,"resources":[]},{"id":"88","title":"Should be more technical","votes":"11","type":"x","order":"2","pct":14.29,"resources":[]},{"id":"89","title":"Should include more HOWTOs","votes":"27","type":"x","order":"3","pct":35.06,"resources":[]}]["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"]["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"]350
    bottom200

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.