PT-2019-13133 · Exiv2+6 · Exiv2+6

Kevinbackhouse

·

Publicado

2019-06-30

·

Atualizado

2023-03-24

·

CVE-2019-13109

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Exiv2 versions prior to 0.27.2
Description The issue is caused by an integer overflow in the handling of PNG image files. Specifically, the PngImage::readMetadata function mishandles the subtraction of iccOffset from chunkLength, leading to a denial of service (SIGSEGV) when a crafted PNG image file is processed.
Recommendations For Exiv2 versions prior to 0.27.2, update to version 0.27.2 or later to resolve the issue.

Exploit

Correção

DoS

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2020:1577
ALT-PU-2019-2468
ALT-PU-2019-2590
CESA-2020_1577
CVE-2019-13109
MGASA-2019-0415
OPENSUSE-SU-2022_4208-1
OPENSUSE-SU-2022_4276-1
RHSA-2020:1577
RHSA-2020_1577
RLSA-2020:1577
SUSE-SU-2022:4208-1
SUSE-SU-2022:4276-1

Produtos afetados

Alt Linux
Almalinux
Centos
Exiv2
Red Hat
Rocky Linux
Suse