file 1:5.32-2ubuntu0.2 source package in Ubuntu

Changelog

file (1:5.32-2ubuntu0.2) bionic-security; urgency=medium

  * SECURITY UPDATE: overflows in do_core_note
    - debian/patches/CVE-2019-8905_8907.patch: limit size of file_printable
      in src/file.h, src/funcs.c, src/readelf.c, src/softmagic.c.
    - CVE-2019-8905
    - CVE-2019-8907
  * SECURITY UPDATE: out-of-bounds read in do_core_note
    - debian/patches/CVE-2019-8906.patch: add bounds check in
      src/readelf.c.
    - CVE-2019-8906

 -- Marc Deslauriers <email address hidden>  Wed, 13 Mar 2019 12:43:04 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Bionic
Original maintainer:
Ubuntu Developers
Architectures:
any
Section:
utils
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
file_5.32.orig.tar.xz 570.7 KiB 07627dc16c9a5b64352b00f24afb8d328b9ecade82afe2e2fa55201d324fd360
file_5.32-2ubuntu0.2.debian.tar.xz 32.6 KiB 676faefe6020355c354683c1477261ab6a4d299bbbae52bdb6004449ad17edbf
file_5.32-2ubuntu0.2.dsc 1.9 KiB 52aa48b2560293f5f5ed113d2ed103086855d10e59535e5f995c097ba0b3b6da

View changes file

Binary packages built by this source

file: Recognize the type of data in a file using "magic" numbers

 The file command is "a file type guesser", a command-line tool that
 tells you in words what kind of data a file contains.
 .
 This package contains the file program itself.

file-dbgsym: debug symbols for file
libmagic-dev: Recognize the type of data in a file using "magic" numbers - development

 This library can be used to classify files according to magic number
 tests.
 .
 This package contains the development files.

libmagic-mgc: File type determination library using "magic" numbers (compiled magic file)

 This package provides the compiled magic file "magic.mgc". It has
 been separated from libmagic1 in order to meet the multiarch
 requirements without breaking applications that expect this file
 at its absolute path.

libmagic1: Recognize the type of data in a file using "magic" numbers - library

 This library can be used to classify files according to magic number
 tests. It implements the core functionality of the file command.

libmagic1-dbgsym: debug symbols for libmagic1