CVE-2019-13112: Medium severity exiv2 vulnerability
Published Jun 30, 2019
·Updated
A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to an std::badalloc exception) via a crafted PNG image file.
Affected Software
9 affected componentsFixes available
redhat/exiv2<0.27.2
0.27.2
debian/exiv2
0.27.3-3+deb11u20.27.3-3+deb11u10.27.6-10.28.3+dfsg-2
exiv2 exiv2<=0.27.1
Fedoraproject Fedora=30
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
Canonical Ubuntu Linux=19.04
Debian Debian Linux=10.0
Event History
Jun 30, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:16 PM
Description
Sep 13, 2024
Data Sourced
via Ubuntu·11:56 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-13112?
CVE-2019-13112 has been classified as a denial of service vulnerability due to uncontrolled memory allocation.
2
How do I fix CVE-2019-13112?
To fix CVE-2019-13112, you should upgrade Exiv2 to version 0.27.2 or later.
3
Which versions of Exiv2 are affected by CVE-2019-13112?
Exiv2 versions prior to 0.27.2 are affected by CVE-2019-13112.
4
Can CVE-2019-13112 be exploited remotely?
Yes, CVE-2019-13112 can be exploited by sending a crafted PNG image to the affected application.
5
What are the potential impacts of CVE-2019-13112 on my system?
The impact of CVE-2019-13112 includes potential crashes of the application, leading to service disruptions.