Description
Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user running file, possibly via a large entity size value in an ELF header (elfhdr.e_shentsize).
Exploits (2)
References (12)
Scores
EPSS
0.0828
EPSS Percentile
92.3%
Details
Status
published
Products (15)
file/file
3.28
file/file
3.30
file/file
3.32
file/file
3.33
file/file
3.34
file/file
3.35
file/file
3.36
file/file
3.37
file/file
3.39
file/file
3.40
... and 5 more
Published
Mar 18, 2003
Tracked Since
Feb 18, 2026