PT-2019-19780 · Libofx+3 · Libofx+3

Cool-Tomato

·

Published

2019-03-11

·

Updated

2024-08-23

·

CVE-2019-9656

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LibOFX version 0.9.14
Description An issue was discovered in LibOFX. There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx sgml.cpp, as demonstrated by ofxdump.
Recommendations For LibOFX version 0.9.14, consider avoiding the use of the OFXApplication::startElement function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2036
ALT-PU-2020-2989
CVE-2019-9656
DLA-2001-1
MGASA-2019-0409
SUSE-SU-2024:3007-1
SUSE-SU-2024_3007-1
USN-4523-1

Affected Products

Alt Linux
Libofx
Suse
Ubuntu