UbuntuUpdates.org

Package "file"

Name: file

Description:

Recognize the type of data in a file using "magic" numbers

Latest version: 1:5.41-3ubuntu0.1
Release: jammy (22.04)
Level: updates
Repository: main
Homepage: https://www.darwinsys.com/file/

Links


Download "file"


Other versions of "file" in Jammy

Repository Area Version
base main 1:5.41-3
security main 1:5.41-3ubuntu0.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1:5.41-3ubuntu0.1 2023-09-12 19:08:07 UTC

  file (1:5.41-3ubuntu0.1) jammy-security; urgency=medium

  * SECURITY UPDATE: buffer over-read in file_copystr
    - debian/patches/CVE-2022-48554.patch: don't use strlcpy to copy the
      string in src/funcs.c.
    - CVE-2022-48554

 -- Marc Deslauriers <email address hidden> Mon, 11 Sep 2023 13:59:06 -0400

CVE-2022-48554 File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: "File" is the name of an Open Source project.



About   -   Send Feedback to @ubuntu_updates