CVE-2019-19451: Medium severity dia vulnerability
When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid codepoint in the current encoding, it enters an endless loop, thus endlessly writing text to stdout. If this launch is from a thumbnailer service, this output will usually be written to disk via the system's logging facility (potentially with elevated privileges), thus filling up the disk and eventually rendering the system unusable. (The filename can be for a nonexistent file.) NOTE: this does not affect an upstream release, but affects certain Linux distribution packages with version numbers such as 0.97.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19451?
CVE-2019-19451 has a medium severity rating due to its potential to cause resource exhaustion.
How do I fix CVE-2019-19451?
To fix CVE-2019-19451, update GNOME Dia to version 2019-11-27 or later.
What vulnerabilities are present in GNOME Dia versions before 2019-11-27?
GNOME Dia versions before 2019-11-27 are vulnerable to an endless loop caused by invalid filename arguments leading to excessive output.
Which operating systems are affected by CVE-2019-19451?
CVE-2019-19451 affects GNOME Dia on Fedora 32, Fedora 33, and openSUSE Leap 15.1.
Is there a workaround for CVE-2019-19451 if I cannot update?
A possible workaround for CVE-2019-19451 is to avoid launching GNOME Dia with invalid filename arguments.