PT-2019-13133 · Exiv2+6 · Exiv2+6

Kevinbackhouse

·

Published

2019-06-30

·

Updated

2023-03-24

·

CVE-2019-13109

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Exiv2 versions prior to 0.27.2
Description The issue is caused by an integer overflow in the handling of PNG image files. Specifically, the PngImage::readMetadata function mishandles the subtraction of iccOffset from chunkLength, leading to a denial of service (SIGSEGV) when a crafted PNG image file is processed.
Recommendations For Exiv2 versions prior to 0.27.2, update to version 0.27.2 or later to resolve the issue.

Exploit

Fix

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020:1577
ALT-PU-2019-2468
ALT-PU-2019-2590
CESA-2020_1577
CVE-2019-13109
MGASA-2019-0415
OPENSUSE-SU-2022_4208-1
OPENSUSE-SU-2022_4276-1
RHSA-2020:1577
RHSA-2020_1577
RLSA-2020:1577
SUSE-SU-2022:4208-1
SUSE-SU-2022:4276-1

Affected Products

Alt Linux
Almalinux
Centos
Exiv2
Red Hat
Rocky Linux
Suse