CVE-2017-1000249

NameCVE-2017-1000249
DescriptionAn issue in file() was introduced in commit 9611f31313a93aa036389c5f3b15eea53510d4d1 (Oct 2016) lets an attacker overwrite a fixed 20 bytes stack buffer with a specially crafted .notes section in an ELF binary. This was fixed in commit 35c94dc6acc418f1ad7f6241a6680e5327495793 (Aug 2017).
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-3965-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
file (PTS)wheezy5.11-2+deb7u8fixed
wheezy (security)5.11-2+deb7u9fixed
jessie1:5.22+15-2+deb8u3fixed
stretch1:5.30-1vulnerable
stretch (security)1:5.30-1+deb9u1fixed
buster, sid1:5.32-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
filesource(unstable)1:5.32-1
filesourcejessie(not affected)
filesourcestretch1:5.30-1+deb9u1DSA-3965-1
filesourcewheezy(not affected)

Notes

[jessie] - file <not-affected> (Vulnerable code introduced later)
[wheezy] - file <not-affected> (Vulnerable code introduced later)
Upstream fix: https://github.com/file/file/commit/35c94dc6acc418f1ad7f6241a6680e5327495793
Introduced by: https://github.com/file/file/commit/9611f31313a93aa036389c5f3b15eea53510d4d1

Search for package or bug name: Reporting problems