CVE-2019-14373: High severity flif vulnerability
An issue was discovered in imagesavepng in image/image-png.cpp in Free Lossless Image Format (FLIF) 0.3. Attackers can trigger a heap-based buffer over-read in libpng via a crafted flif file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-14373?
CVE-2019-14373 is a vulnerability in Free Lossless Image Format (FLIF) 0.3 that allows attackers to trigger a heap-based buffer over-read in libpng via a crafted flif file.
How severe is CVE-2019-14373?
CVE-2019-14373 has a severity value of 7.8 which is considered high.
What software versions are affected by CVE-2019-14373?
Any version of Flif Flif 0.3 is affected by CVE-2019-14373.
How can I fix CVE-2019-14373?
There is currently no fix available for CVE-2019-14373. It is recommended to avoid opening or processing untrusted flif files.
Where can I find more information about CVE-2019-14373?
More information about CVE-2019-14373 can be found at the following reference: [GitHub - FLIF-hub/FLIF](https://github.com/FLIF-hub/FLIF/issues/541)