Bug 1096974 - (CVE-2018-10360) VUL-1: CVE-2018-10360: file: The do_core_note function in readelf.c in libmagic.a in file 5.33 allows remoteattackers to cause a denial of service (out-of-bounds read and applicationcrash) via a crafted ELF file.
(CVE-2018-10360)
VUL-1: CVE-2018-10360: file: The do_core_note function in readelf.c in libmag...
Status: REOPENED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P4 - Low : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/207803/
CVSSv3:SUSE:CVE-2018-10360:3.3:(AV:L/...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2018-06-11 14:04 UTC by Marcus Meissner
Modified: 2020-08-04 08:12 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2018-06-11 14:04:11 UTC
CVE-2018-10360

The do_core_note function in readelf.c in libmagic.a in file 5.33 allows remote
attackers to cause a denial of service (out-of-bounds read and application
crash) via a crafted ELF file.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-10360
https://github.com/file/file/commit/a642587a9c9e2dd7feacdf513c3643ce26ad3c22
Comment 1 Dr. Werner Fink 2018-06-11 14:09:55 UTC
(In reply to Marcus Meissner from comment #0)
> CVE-2018-10360
> 
> The do_core_note function in readelf.c in libmagic.a in file 5.33 allows
> remote
> attackers to cause a denial of service (out-of-bounds read and application
> crash) via a crafted ELF file.
> 
> References:
> http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-10360
> https://github.com/file/file/commit/a642587a9c9e2dd7feacdf513c3643ce26ad3c22

What is about 5.32 and below?  We do not have file 5.33 anywhere
Comment 2 Marcus Meissner 2018-06-11 14:25:28 UTC
the code looks the same in sle11 file and sle12 file.
Comment 3 Dr. Werner Fink 2018-06-12 15:30:35 UTC
SR#166803 SLES11
SR#166804 SLES12 Leap42.3
SR#166805 SLES15 Leap15
SR#616342 Factory
Comment 4 Swamp Workflow Management 2018-06-12 16:00:09 UTC
This is an autogenerated message for OBS integration:
This bug (1096974) was mentioned in
https://build.opensuse.org/request/show/616342 Factory / file
Comment 6 Swamp Workflow Management 2018-06-13 08:30:05 UTC
This is an autogenerated message for OBS integration:
This bug (1096974) was mentioned in
https://build.opensuse.org/request/show/616455 Factory / file
Comment 7 Dr. Werner Fink 2018-09-17 12:16:36 UTC
SR reached targets
Comment 10 Swamp Workflow Management 2019-03-07 23:09:54 UTC
SUSE-SU-2019:0571-1: An update that solves four vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 1096974,1096984,1126117,1126118,1126119
CVE References: CVE-2018-10360,CVE-2019-8905,CVE-2019-8906,CVE-2019-8907
Sources used:
SUSE Linux Enterprise Module for Development Tools 15 (src):    python-magic-5.32-7.5.1
SUSE Linux Enterprise Module for Basesystem 15 (src):    file-5.32-7.5.1, python-magic-5.32-7.5.1
Comment 11 Swamp Workflow Management 2019-04-02 16:19:52 UTC
SUSE-SU-2019:0839-1: An update that solves four vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 1096974,1096984,1126117,1126118,1126119
CVE References: CVE-2018-10360,CVE-2019-8905,CVE-2019-8906,CVE-2019-8907
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP4 (src):    file-5.22-10.12.2, python-magic-5.22-10.12.2
SUSE Linux Enterprise Software Development Kit 12-SP3 (src):    file-5.22-10.12.2, python-magic-5.22-10.12.2
SUSE Linux Enterprise Server 12-SP4 (src):    file-5.22-10.12.2
SUSE Linux Enterprise Server 12-SP3 (src):    file-5.22-10.12.2
SUSE Linux Enterprise Desktop 12-SP4 (src):    file-5.22-10.12.2
SUSE Linux Enterprise Desktop 12-SP3 (src):    file-5.22-10.12.2
SUSE CaaS Platform ALL (src):    file-5.22-10.12.2
SUSE CaaS Platform 3.0 (src):    file-5.22-10.12.2
OpenStack Cloud Magnum Orchestration 7 (src):    file-5.22-10.12.2

*** NOTE: This information is not intended to be used for external
    communication, because this may only be a partial fix.
    If you have questions please reach out to maintenance coordination.