CVE-2019-14369: Medium severity exiv2 vulnerability
Published Jul 28, 2019
·Updated
Exiv2::PngImage::readMetadata() in pngimage.cpp in Exiv2 0.27.99.0 allows attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file.
Affected Software
2 affected components
exiv2 exiv2=0.27.99.0
Debian Debian Linux=10.0
Event History
Jul 28, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-14369?
CVE-2019-14369 is considered to have a medium severity level due to its potential for causing denial of service.
2
How does CVE-2019-14369 affect Exiv2?
CVE-2019-14369 allows attackers to cause a heap-based buffer over-read when Exiv2 processes a crafted PNG image file.
3
Which versions of Exiv2 are vulnerable to CVE-2019-14369?
Exiv2 version 0.27.99.0 is specifically vulnerable to CVE-2019-14369.
4
How can I mitigate CVE-2019-14369?
To mitigate CVE-2019-14369, consider upgrading Exiv2 to a version that has addressed this vulnerability.
5
Is Debian GNU/Linux affected by CVE-2019-14369?
Yes, Debian GNU/Linux 10.0 is affected by CVE-2019-14369, particularly when running the vulnerable version of Exiv2.