First published: Sun Jul 28 2019(Updated: )
Exiv2::PngImage::readMetadata() in pngimage.cpp in Exiv2 0.27.99.0 allows attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Dos2unix | =0.27.99.0 | |
Debian | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14369 is considered to have a medium severity level due to its potential for causing denial of service.
CVE-2019-14369 allows attackers to cause a heap-based buffer over-read when Exiv2 processes a crafted PNG image file.
Exiv2 version 0.27.99.0 is specifically vulnerable to CVE-2019-14369.
To mitigate CVE-2019-14369, consider upgrading Exiv2 to a version that has addressed this vulnerability.
Yes, Debian GNU/Linux 10.0 is affected by CVE-2019-14369, particularly when running the vulnerable version of Exiv2.