First published: Sun Jul 28 2019(Updated: )
An issue was discovered in image_save_png in image/image-png.cpp in Free Lossless Image Format (FLIF) 0.3. Attackers can trigger a heap-based buffer over-read in libpng via a crafted flif file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Flif Flif | =0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14373 is a vulnerability in Free Lossless Image Format (FLIF) 0.3 that allows attackers to trigger a heap-based buffer over-read in libpng via a crafted flif file.
CVE-2019-14373 has a severity value of 7.8 which is considered high.
Any version of Flif Flif 0.3 is affected by CVE-2019-14373.
There is currently no fix available for CVE-2019-14373. It is recommended to avoid opening or processing untrusted flif files.
More information about CVE-2019-14373 can be found at the following reference: [GitHub - FLIF-hub/FLIF](https://github.com/FLIF-hub/FLIF/issues/541)