Search

Find a vulnerability

Search criteria

    Related vulnerabilities

    USN-3911-1 (UBUNTU-CVE-2019-8904)

    Vulnerability from osv_ubuntu – Published: 2019-03-18 12:50 – Updated: 2026-04-22 07:36 – Source website
    VLAI
    Summary
    file vulnerabilities
    Details

    It was discovered that file incorrectly handled certain malformed ELF files. An attacker could use this issue to cause a denial of service, or possibly execute arbitrary code.


    {
      "affected": [
        {
          "database_specific": {
            "cves_map": {
              "cves": [
                {
                  "id": "CVE-2019-8905",
                  "severity": [
                    {
                      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L",
                      "type": "CVSS_V3"
                    },
                    {
                      "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                      "type": "CVSS_V3"
                    },
                    {
                      "score": "low",
                      "type": "Ubuntu"
                    }
                  ]
                },
                {
                  "id": "CVE-2019-8907",
                  "severity": [
                    {
                      "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                      "type": "CVSS_V3"
                    },
                    {
                      "score": "medium",
                      "type": "Ubuntu"
                    }
                  ]
                }
              ],
              "ecosystem": "Ubuntu:16.04:LTS"
            }
          },
          "ecosystem_specific": {
            "availability": "No subscription required",
            "binaries": [
              {
                "binary_name": "file",
                "binary_version": "1:5.25-2ubuntu1.2"
              },
              {
                "binary_name": "libmagic1",
                "binary_version": "1:5.25-2ubuntu1.2"
              },
              {
                "binary_name": "python-magic",
                "binary_version": "1:5.25-2ubuntu1.2"
              },
              {
                "binary_name": "python3-magic",
                "binary_version": "1:5.25-2ubuntu1.2"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:16.04:LTS",
            "name": "file",
            "purl": "pkg:deb/ubuntu/file@1:5.25-2ubuntu1.2?arch=source\u0026distro=xenial"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1:5.25-2ubuntu1.2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1:5.22+15-2ubuntu1",
            "1:5.25-2ubuntu1",
            "1:5.25-2ubuntu1.1"
          ]
        },
        {
          "database_specific": {
            "cves_map": {
              "cves": [
                {
                  "id": "CVE-2019-8905",
                  "severity": [
                    {
                      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L",
                      "type": "CVSS_V3"
                    },
                    {
                      "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                      "type": "CVSS_V3"
                    },
                    {
                      "score": "low",
                      "type": "Ubuntu"
                    }
                  ]
                },
                {
                  "id": "CVE-2019-8906",
                  "severity": [
                    {
                      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L",
                      "type": "CVSS_V3"
                    },
                    {
                      "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                      "type": "CVSS_V3"
                    },
                    {
                      "score": "medium",
                      "type": "Ubuntu"
                    }
                  ]
                },
                {
                  "id": "CVE-2019-8907",
                  "severity": [
                    {
                      "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                      "type": "CVSS_V3"
                    },
                    {
                      "score": "medium",
                      "type": "Ubuntu"
                    }
                  ]
                }
              ],
              "ecosystem": "Ubuntu:18.04:LTS"
            }
          },
          "ecosystem_specific": {
            "availability": "No subscription required",
            "binaries": [
              {
                "binary_name": "file",
                "binary_version": "1:5.32-2ubuntu0.2"
              },
              {
                "binary_name": "libmagic-mgc",
                "binary_version": "1:5.32-2ubuntu0.2"
              },
              {
                "binary_name": "libmagic1",
                "binary_version": "1:5.32-2ubuntu0.2"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:18.04:LTS",
            "name": "file",
            "purl": "pkg:deb/ubuntu/file@1:5.32-2ubuntu0.2?arch=source\u0026distro=bionic"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1:5.32-2ubuntu0.2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1:5.32-1",
            "1:5.32-2",
            "1:5.32-2ubuntu0.1"
          ]
        }
      ],
      "aliases": [],
      "details": "It was discovered that file incorrectly handled certain malformed ELF\nfiles. An attacker could use this issue to cause a denial of service, or\npossibly execute arbitrary code.\n",
      "id": "USN-3911-1",
      "modified": "2026-04-22T07:36:36Z",
      "published": "2019-03-18T12:50:20Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://ubuntu.com/security/notices/USN-3911-1"
        },
        {
          "type": "REPORT",
          "url": "https://ubuntu.com/security/CVE-2019-8904"
        },
        {
          "type": "REPORT",
          "url": "https://ubuntu.com/security/CVE-2019-8905"
        },
        {
          "type": "REPORT",
          "url": "https://ubuntu.com/security/CVE-2019-8906"
        },
        {
          "type": "REPORT",
          "url": "https://ubuntu.com/security/CVE-2019-8907"
        }
      ],
      "related": [],
      "schema_version": "1.7.0",
      "summary": "file vulnerabilities",
      "upstream": [
        "UBUNTU-CVE-2019-8904",
        "UBUNTU-CVE-2019-8905",
        "UBUNTU-CVE-2019-8906",
        "UBUNTU-CVE-2019-8907"
      ]
    }