CVE-2019-13110: Integer Overflow
Published Jun 30, 2019
·Updated
A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted CRW image file.
Affected Software
8 affected componentsFixes available
exiv2 exiv2<=0.27.1
Fedoraproject Fedora=30
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
Canonical Ubuntu Linux=19.04
Debian Debian Linux=10.0
debian/exiv2
0.27.3-3+deb11u20.27.3-3+deb11u10.27.6-10.28.5+dfsg-10.28.7+dfsg-2
Remediation
Patch Available
Event History
Jun 30, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 20, 2026
Data Sourced
via Ubuntu·06:23 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·06:23 PM
DescriptionAffected Software
Data Sourced
via Launchpad·06:23 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13110?
CVE-2019-13110 has been assessed with a severity level that indicates a potential denial of service vulnerability.
2
Which versions of Exiv2 are affected by CVE-2019-13110?
CVE-2019-13110 affects Exiv2 versions up to and including 0.27.1.
3
How do I fix CVE-2019-13110?
To fix CVE-2019-13110, update Exiv2 to versions 0.27.3-3+deb11u2, 0.27.3-3+deb11u1, 0.27.6-1, or 0.28.3+dfsg-2.
4
Is there a denial of service risk with CVE-2019-13110?
Yes, CVE-2019-13110 can lead to a denial of service through an integer overflow in the readDirectory function.
5
What type of file can exploit CVE-2019-13110?
CVE-2019-13110 can be exploited using a specially crafted CRW image file.