PT-2019-17467 · Gimp+2 · Xcftools+2

Claudio Bozzato

·

Published

2019-11-21

·

Updated

2023-03-29

·

CVE-2019-5086

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions xcftools version 1.0.7
Description An integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries. This vulnerability can occur while walking through tiles and could be exploited to corrupt memory and execute arbitrary code. A victim would need to open a specially crafted XCF file to trigger this issue.
Recommendations For version 1.0.7, consider avoiding the use of the flattenIncrementally function in the xcf2png and xcf2pnm binaries until a patch is available. As a temporary workaround, restrict the opening of XCF files from untrusted sources to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Integer Overflow

Weakness Enumeration

Related Identifiers

CVE-2019-5086
DLA-2553-1
DLA-2553-2
USN-5988-1

Affected Products

Linuxmint
Ubuntu
Xcftools