PT-2020-10385 · Gnome+3 · Cairo+5

Published

2019-03-18

·

Updated

2022-10-14

·

CVE-2019-20326

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions gThumb versions prior to 3.8.3 Linux Mint Pix versions prior to 2.4.5
Description A heap-based buffer overflow in the cairo image surface create from jpeg() function allows attackers to cause a crash and potentially execute arbitrary code via a crafted JPEG file. This issue is related to the extensions/cairo io/cairo-image-surface-jpeg.c file.
Recommendations For gThumb versions prior to 3.8.3, update to version 3.8.3 or later to resolve the issue. For Linux Mint Pix versions prior to 2.4.5, update to version 2.4.5 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the cairo image surface create from jpeg() function until a patch is available.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1459
ALT-PU-2019-3374
ALT-PU-2020-1012
ALT-PU-2020-2872
CVE-2019-20326
DLA-2066-1
DLA-2749-1
MGASA-2020-0056
MGASA-2021-0090
USN-5680-1
USN-5681-1

Affected Products

Alt Linux
Linuxmint
Linux Mint Pix
Ubuntu
Cairo
Gthumb