CVE-2019-13111: Integer Overflow
Published Jun 30, 2019
·Updated
A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (large heap allocation followed by a very long running loop) via a crafted WEBP image file.
Affected Software
3 affected componentsFixes available
redhat/exiv2<0.27.2
0.27.2
exiv2 exiv2<=0.27.1
fedoraproject fedora=30
Remediation
Patch Available
Patch Available
Event History
Jun 30, 2019
CVE Published
via MITRE·10:20 PM
Data Sourced
via MITRE·10:20 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13111?
CVE-2019-13111 has a high severity as it leads to potential denial of service due to integer overflow.
2
How do I fix CVE-2019-13111?
To fix CVE-2019-13111, upgrade to Exiv2 version 0.27.2 or later.
3
What type of vulnerability is CVE-2019-13111?
CVE-2019-13111 is an integer overflow vulnerability that affects the handling of WEBP image files.
4
Which versions of Exiv2 are affected by CVE-2019-13111?
All Exiv2 versions up to and including 0.27.1 are affected by CVE-2019-13111.
5
Can CVE-2019-13111 be exploited remotely?
Yes, CVE-2019-13111 can be exploited remotely if a crafted WEBP image file is processed.