PT-2019-13132 · Exiv2+2 · Exiv2+2

Kevinbackhouse

·

Published

2019-06-30

·

Updated

2024-06-15

·

CVE-2019-13108

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Exiv2 versions prior to 0.27.2
Description The issue is caused by an integer overflow in the Exiv2 library, which can be triggered by a crafted PNG image file. This overflow occurs because the PngImage::readMetadata function mishandles a zero value for the iccOffset variable, leading to a denial of service (SIGSEGV).
Recommendations For Exiv2 versions prior to 0.27.2, update to version 0.27.2 or later to resolve the issue.

Exploit

Fix

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2468
ALT-PU-2019-2590
CVE-2019-13108
MGASA-2019-0415
OESA-2021-1451
OESA-2022-1955
OESA-2022-2044
OPENSUSE-SU-2022_3889-1
OPENSUSE-SU-2024:12381-1
SUSE-SU-2022:3889-1

Affected Products

Alt Linux
Exiv2
Suse