CVE-2017-1000249

Source
https://cve.org/CVERecord?id=CVE-2017-1000249
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-1000249.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-1000249
Downstream
Related
Published
2017-09-11T19:29:00.200Z
Modified
2026-07-08T15:10:07.937237Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

An issue in file() was introduced in commit 9611f31313a93aa036389c5f3b15eea53510d4d1 (Oct 2016) lets an attacker overwrite a fixed 20 bytes stack buffer with a specially crafted .notes section in an ELF binary. This was fixed in commit 35c94dc6acc418f1ad7f6241a6680e5327495793 (Aug 2017).

References

Affected packages

Git / github.com/file/file

Affected ranges

Type
GIT
Repo
https://github.com/file/file
Events
Database specific
{
    "cpe": "cpe:2.3:a:file_project:file:5.29:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "5.29"
        },
        {
            "last_affected": "5.29"
        }
    ],
    "source": [
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

5.*
5.29
Other
FILE5_29
FILE5_30
FILE5_31

Database specific

vanir_signatures_modified
"2026-07-08T15:10:07Z"
vanir_signatures
[
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "191730419508807807995728450003017890109",
                "255685428453647614123441016389726967408",
                "165778089394274387787587373511134378635",
                "332407869254594291647053825146415379105",
                "330899916478574045905968768894139584839",
                "158136468176192798324936030520550183940",
                "193169790860533737710285639127229560049"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/file/file/commit/35c94dc6acc418f1ad7f6241a6680e5327495793",
        "id": "CVE-2017-1000249-fd5cd05d",
        "target": {
            "file": "src/readelf.c"
        }
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-1000249.json"