Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 918554 (CVE-2022-48554) - <sys-apps/file-5.42: stack buffer overread
Summary: <sys-apps/file-5.42: stack buffer overread
Status: RESOLVED FIXED
Alias: CVE-2022-48554
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL: https://bugs.astron.com/view.php?id=310
Whiteboard: A3 [glsa+]
Keywords:
Depends on:
Blocks:
 
Reported: 2023-11-25 19:49 UTC by John Helmert III
Modified: 2024-09-22 06:05 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-11-25 19:49:25 UTC
CVE-2022-48554:

File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: "File" is the name of an Open Source project.

A fix isn't explicitly referenced, but upstream's tracker calls this fixed in >=5.42.
Comment 1 Larry the Git Cow gentoo-dev 2024-09-22 06:05:09 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=a6214968cd131e222d57f5ee5fcbafe13e8f88af

commit a6214968cd131e222d57f5ee5fcbafe13e8f88af
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2024-09-22 06:04:59 +0000
Commit:     Hans de Graaff <graaff@gentoo.org>
CommitDate: 2024-09-22 06:05:07 +0000

    [ GLSA 202409-06 ] file: Stack Buffer Overread
    
    Bug: https://bugs.gentoo.org/918554
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: Hans de Graaff <graaff@gentoo.org>

 glsa-202409-06.xml | 42 ++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 42 insertions(+)