PT-2019-17467 · Gimp+2 · Xcftools+2
Claudio Bozzato
·
Published
2019-11-21
·
Updated
2023-03-29
·
CVE-2019-5086
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
xcftools version 1.0.7
Description
An integer overflow vulnerability exists in the
flattenIncrementally function in the xcf2png and xcf2pnm binaries. This vulnerability can occur while walking through tiles and could be exploited to corrupt memory and execute arbitrary code. A victim would need to open a specially crafted XCF file to trigger this issue.Recommendations
For version 1.0.7, consider avoiding the use of the
flattenIncrementally function in the xcf2png and xcf2pnm binaries until a patch is available. As a temporary workaround, restrict the opening of XCF files from untrusted sources to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Memory Corruption
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Ubuntu
Xcftools