CVE-2019-1010174: Command Injection
Published Jul 25, 2019
·Updated
CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: loadnetwork() function. The attack vector is: Loading an image from a user-controllable url can lead to command injection, because no string sanitization is done on the url. The fixed version is: v.2.3.4.
Affected Software
3 affected components
CImg CImg Library<2.3.4
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Event History
Jul 25, 2019
CVE Published
via MITRE·01:12 PM
Data Sourced
via MITRE·01:12 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-1010174.
2
What is the severity of CVE-2019-1010174?
The severity of CVE-2019-1010174 is critical with a severity value of 9.8.
3
What is the impact of CVE-2019-1010174?
The impact of CVE-2019-1010174 is remote code execution (RCE).
4
Which component is affected by CVE-2019-1010174?
The load_network() function of the CImg Library v.2.3.3 and earlier is affected by CVE-2019-1010174.
5
How can CVE-2019-1010174 be exploited?
CVE-2019-1010174 can be exploited by loading an image from a user-controllable URL, which can lead to command injection.