CVE-2019-13108: Integer Overflow
Published Jun 30, 2019
·Updated
An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a zero value for iccOffset.
Affected Software
2 affected components
exiv2 exiv2<=0.27.1
fedoraproject fedora=30
Remediation
Patch Available
Event History
Jun 30, 2019
CVE Published
via MITRE·10:19 PM
Data Sourced
via MITRE·10:19 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13108?
CVE-2019-13108 has a severity rating that typically indicates it can lead to denial of service due to an integer overflow.
2
How do I fix CVE-2019-13108?
To fix CVE-2019-13108, update Exiv2 to version 0.27.2 or later, which addresses this vulnerability.
3
Which versions of Exiv2 are affected by CVE-2019-13108?
CVE-2019-13108 affects Exiv2 versions up to and including 0.27.1.
4
Can CVE-2019-13108 be exploited remotely?
Yes, CVE-2019-13108 can be exploited remotely by processing a specially crafted PNG file.
5
What type of attack does CVE-2019-13108 facilitate?
CVE-2019-13108 can facilitate a denial of service attack, causing the application to crash.