PT-2019-13132 · Exiv2+2 · Exiv2+2

Kevinbackhouse

·

Publicado

2019-06-30

·

Atualizado

2024-06-15

·

CVE-2019-13108

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Exiv2 versions prior to 0.27.2
Description The issue is caused by an integer overflow in the Exiv2 library, which can be triggered by a crafted PNG image file. This overflow occurs because the PngImage::readMetadata function mishandles a zero value for the iccOffset variable, leading to a denial of service (SIGSEGV).
Recommendations For Exiv2 versions prior to 0.27.2, update to version 0.27.2 or later to resolve the issue.

Exploit

Correção

DoS

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2468
ALT-PU-2019-2590
CVE-2019-13108
MGASA-2019-0415
OESA-2021-1451
OESA-2022-1955
OESA-2022-2044
OPENSUSE-SU-2022_3889-1
OPENSUSE-SU-2024:12381-1
SUSE-SU-2022:3889-1

Produtos afetados

Alt Linux
Exiv2
Suse