CVE-2019-13109: Integer Overflow
Published Jun 30, 2019
·Updated
An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a chunkLength - iccOffset subtraction.
Affected Software
3 affected componentsFixes available
redhat/exiv2<0.27.2
0.27.2
exiv2 exiv2<=0.27.1
fedoraproject fedora=30
Remediation
Patch Available
Patch Available
Event History
Jun 30, 2019
CVE Published
via MITRE·10:20 PM
Data Sourced
via MITRE·10:20 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13109?
CVE-2019-13109 has a severity rating that allows for denial of service through an integer overflow, potentially leading to application crashes.
2
How do I fix CVE-2019-13109?
To fix CVE-2019-13109, you should upgrade Exiv2 to version 0.27.2 or later.
3
Which versions of Exiv2 are affected by CVE-2019-13109?
CVE-2019-13109 affects Exiv2 versions up to and including 0.27.1.
4
What type of vulnerability is CVE-2019-13109?
CVE-2019-13109 is classified as an integer overflow vulnerability that can be exploited via malformed PNG image files.
5
Can CVE-2019-13109 be exploited remotely?
Yes, CVE-2019-13109 can potentially be exploited remotely by an attacker using a crafted PNG image.