PT-2019-6322 · Exiv2+1 · Exiv2+1

Cuanduo

·

Published

2019-07-12

·

Updated

2023-01-13

·

CVE-2019-14369

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Exiv2 version 0.27.99.0
Description The issue is related to a heap-based buffer over-read in the Exiv2::PngImage::readMetadata() function, located in the pngimage.cpp component of the Exiv2 library. This can be exploited by attackers using a crafted image file, potentially leading to a denial of service. The vulnerability is associated with reading beyond the valid boundaries of a data buffer.
Recommendations For Exiv2 version 0.27.99.0, consider disabling the Exiv2::PngImage::readMetadata() function as a temporary workaround until a patch is available. Restrict access to the pngimage.cpp component to minimize the risk of exploitation. Avoid using the affected library with untrusted image files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2023-01656
CVE-2019-14369
DLA-3265-1

Affected Products

Astra Linux
Exiv2