CVE-2019-10672: Input Validation
Published Mar 31, 2019
·Updated
Last updated 25 August 2025
Other sources
treeRead in hdf/btree.c in libmysofa before 0.7 does not properly validate multiplications and additions.
— MITRE
Affected Software
2 affected componentsFixes available
Symonics libmysofa<0.7
debian/libmysofa
1.2~dfsg0-11.3.1~dfsg0-11.3.3+dfsg-1
Remediation
Event History
Mar 31, 2019
CVE Published
via MITRE·04:48 PM
Data Sourced
via MITRE·04:48 PM
Description
Data Sourced
via NVD·05:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 8, 2024
Data Sourced
via Launchpad·10:39 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·10:10 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·10:11 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-10672?
The severity of CVE-2019-10672 is critical with a severity value of 9.8.
2
What is the description of CVE-2019-10672?
CVE-2019-10672 is a vulnerability in libmysofa before 0.7 that allows for improper validation of multiplications and additions.
3
What software is affected by CVE-2019-10672?
The affected software by CVE-2019-10672 is Symonics libmysofa version up to 0.7.
4
How can I fix CVE-2019-10672?
To fix CVE-2019-10672, it is recommended to update to the latest version of Symonics libmysofa (0.7 or higher).
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2019-10672?
The Common Weakness Enumeration (CWE) ID for CVE-2019-10672 is CWE-20.