CVE-2019-19451: Medium severity dia vulnerability

Published Nov 29, 2019
·
Updated

When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid codepoint in the current encoding, it enters an endless loop, thus endlessly writing text to stdout. If this launch is from a thumbnailer service, this output will usually be written to disk via the system's logging facility (potentially with elevated privileges), thus filling up the disk and eventually rendering the system unusable. (The filename can be for a nonexistent file.) NOTE: this does not affect an upstream release, but affects certain Linux distribution packages with version numbers such as 0.97.3.

Affected Software

4 affected components
Gnome Dia<2019-11-27
Fedoraproject Fedora=32
Fedoraproject Fedora=33
openSUSE Leap=15.1

Event History

Nov 29, 2019
CVE Published
via MITRE·10:54 PM
Data Sourced
via MITRE·10:54 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2019-19451?

CVE-2019-19451 has a medium severity rating due to its potential to cause resource exhaustion.

2

How do I fix CVE-2019-19451?

To fix CVE-2019-19451, update GNOME Dia to version 2019-11-27 or later.

3

What vulnerabilities are present in GNOME Dia versions before 2019-11-27?

GNOME Dia versions before 2019-11-27 are vulnerable to an endless loop caused by invalid filename arguments leading to excessive output.

4

Which operating systems are affected by CVE-2019-19451?

CVE-2019-19451 affects GNOME Dia on Fedora 32, Fedora 33, and openSUSE Leap 15.1.

5

Is there a workaround for CVE-2019-19451 if I cannot update?

A possible workaround for CVE-2019-19451 is to avoid launching GNOME Dia with invalid filename arguments.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203