CVE-2019-13113: Medium severity exiv2 vulnerability
Published Jun 30, 2019
·Updated
Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure) via an invalid data location in a CRW image file.
Affected Software
8 affected componentsFixes available
redhat/exiv2<0.27.2
0.27.2
debian/exiv2
0.27.3-3+deb11u20.27.3-3+deb11u10.27.6-10.28.3+dfsg-2
exiv2 exiv2<=0.27.1
fedoraproject fedora=30
Ubuntu=16.04
Ubuntu=18.04
Ubuntu=18.10
Ubuntu=19.04
Remediation
Patch Available
Event History
Jun 30, 2019
CVE Published
via MITRE·10:21 PM
Data Sourced
via MITRE·10:21 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:16 PM
Description
Sep 13, 2024
Data Sourced
via Ubuntu·11:56 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-13113?
CVE-2019-13113 is classified as a denial of service vulnerability.
2
How do I fix CVE-2019-13113?
To fix CVE-2019-13113, upgrade Exiv2 to version 0.27.2 or higher.
3
What versions of Exiv2 are affected by CVE-2019-13113?
CVE-2019-13113 affects Exiv2 versions up to and including 0.27.1.
4
Can CVE-2019-13113 lead to a complete system compromise?
CVE-2019-13113 does not lead to a complete system compromise; it results in a denial of service.
5
Which operating systems are impacted by CVE-2019-13113?
CVE-2019-13113 impacts Exiv2 users across various distributions, including Red Hat, Debian, and multiple versions of Ubuntu.