CVE-2019-17533: High severity libmatio vulnerability
Published Oct 13, 2019
·Updated
MatVarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read in strdupvprintf when uninitialized memory is accessed.
Affected Software
2 affected components
Matio Project Matio=1.5.17
Debian Debian Linux=8.0
Remediation
Event History
Oct 13, 2019
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-17533?
CVE-2019-17533 is classified as a medium severity vulnerability due to its potential for causing a heap-based buffer over-read.
2
How do I fix CVE-2019-17533?
To address CVE-2019-17533, update to MATIO version 1.5.18 or later, which includes the necessary patches.
3
What type of vulnerability is CVE-2019-17533?
CVE-2019-17533 is a heap-based buffer over-read vulnerability that can lead to accessing uninitialized memory.
4
Which software is affected by CVE-2019-17533?
CVE-2019-17533 affects MATIO version 1.5.17 and Debian Linux 8.0.
5
What are the consequences of exploiting CVE-2019-17533?
Exploiting CVE-2019-17533 may lead to information disclosure or application crashes due to uninitialized memory access.