CVE-2019-3572: Medium severity Libming Libming vulnerability
Published Jan 2, 2019
·Updated
An issue was discovered in libming 0.4.8. There is a heap-based buffer over-read in the function writePNG in the file util/dbl2png.c of the dbl2png command-line program. Because this is associated with an erroneous call to pngwriterow in libpng, an out-of-bounds write might occur for some memory layouts.
Affected Software
1 affected component
Libming Libming=0.4.8
Event History
Jan 2, 2019
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is CVE-2019-3572?
CVE-2019-3572 is a vulnerability in libming 0.4.8 that allows for a heap-based buffer over-read, leading to potential out-of-bounds write.
2
What software is affected by CVE-2019-3572?
The vulnerability affects libming 0.4.8.
3
What is the severity of CVE-2019-3572?
The severity of CVE-2019-3572 is medium with a CVSS score of 6.5.
4
How can I fix CVE-2019-3572?
To fix CVE-2019-3572, update libming to a version that does not contain the vulnerability.
5
Where can I find more information about CVE-2019-3572?
More information about CVE-2019-3572 can be found at this link: https://github.com/libming/libming/issues/169