First published: Thu Aug 29 2019(Updated: )
An integer overflow in whoopsie before versions 0.2.52.5ubuntu0.1, 0.2.62ubuntu0.1, 0.2.64ubuntu0.1, 0.2.66, results in an out-of-bounds write to a heap allocated buffer when processing large crash dumps. This results in a crash or possible code-execution in the context of the whoopsie process.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =18.04 | |
Ubuntu Linux | =18.10 | |
Ubuntu Linux | =19.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =18.10 | |
Ubuntu | =19.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-11476 is classified as critical due to the potential for code execution resulting from an integer overflow.
To fix CVE-2019-11476, update whoopsie to version 0.2.52.5ubuntu0.1 or later for Ubuntu 16.04, version 0.2.62ubuntu0.1 or later for Ubuntu 18.04, version 0.2.64ubuntu0.1 or later for Ubuntu 18.10, or version 0.2.66 or later for Ubuntu 19.04.
Affected versions include Ubuntu 16.04 LTS, 18.04 LTS, 18.10, and 19.04.
CVE-2019-11476 is an integer overflow vulnerability that can lead to an out-of-bounds write.
The potential impact of CVE-2019-11476 includes application crashes and possible code execution in the context of the affected service.