file: Stack Buffer Overread A vulnerability has been discovered in file, which could lead to a denial of service. file 2024-09-22 2024-09-22 918554 remote 5.42 5.42

The file utility attempts to identify a file’s format by scanning binary data for patterns.

Multiple vulnerabilities have been discovered in file. Please review the CVE identifiers referenced below for details.

File has an stack-based buffer over-read in file_copystr in funcs.c.

There is no known workaround at this time.

All file users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=sys-apps/file-5.42"
CVE-2022-48554 graaff graaff