7.2
CWE
119
Advisory Published
Updated

CVE-2019-6001: Buffer Overflow

First published: Tue Aug 06 2019(Updated: )

Buffer overflow in PTP (Picture Transfer Protocol) of EOS series digital cameras (EOS-1D X firmware version 2.1.0 and earlier, EOS-1D X MKII firmware version 1.1.6 and earlier, EOS-1D C firmware version 1.4.1 and earlier, EOS 5D MARK III firmware version 1.3.5 and earlier, EOS 5D MARK IV firmware version 1.2.0 and earlier, EOS 5DS firmware version 1.1.2 and earlier, EOS 5DS R firmware version 1.1.2 and earlier, EOS 6D firmware version 1.1.8 and earlier, EOS 6D MARK II firmware version 1.0.4 and earlier, EOS 7D MARK II firmware version 1.1.2 and earlier, EOS 70 D firmware version 1.1.2 and earlier, EOS 80 D firmware version 1.0.2 and earlier, EOS KISS X7I / EOS D REBEL T5I / EOS 700D firmware version 1.1.5 and earlier, EOS KISS X8I / EOS D REBEL T6I / EOS 750D firmware version 1.0.0 and earlier, EOS KISS X9I / EOS D REBEL T7I / EOS 800D firmware version 1.0.1 and earlier, EOS KISS X7 / EOS D REBEL SL1 / EOS 100D firmware version 1.0.1 and earlier, EOS KISS X9 / EOS D REBEL SL2 / EOS 200D firmware version 1.0.1 and earlier, EOS KISS X10 / EOS D REBEL SL3 / EOS 200D / EOS 250D firmware version 1.0.1 and earlier, EOS 8000D / EOS D REBEL T6S / EOS 760D firmware version 1.0.0 and earlier, EOS 9000D / EOS 77D firmware version 1.0.2 and earlier, EOS KISS X70 / EOS D REBEL T5 / EOS 1200D firmware version 1.0.2 and earlier, EOS D REBEL T5 RE / EOS 1200D MG / EOS HI firmware version 1.0.2 and earlier, EOS KISS X80 / EOS D REBEL T6 / EOS 1300D firmware version 1.1.0 and earlier, EOS KISS X90 / EOS D REBEL T7 / EOS 1500D / EOS 2000D firmware version 1.0.0 and earlier, EOS D REBEL T100 / EOS 3000D / EOS 4000D firmware version 1.0.0 and earlier, EOS R firmware version 1.3.0 and earlier, EOS RP firmware version 1.2.0 and earlier, EOS RP GOLD firmware version 1.2.0 and earlier, EOS M2 firmware version 1.0.3 and earlier, EOS M3 firmware version 1.2.0 and earlier, EOS M5 firmware version 1.0.1 and earlier, EOS M6 firmware version 1.0.1 and earlier, EOS M6(China) firmware version 5.0.0 and earlier, EOS M10 firmware version 1.1.0 and earlier, EOS M100 firmware version 1.0.0 and earlier, EOS KISS M / EOS M50 firmware version 1.0.2 and earlier) and PowerShot SX740 HS firmware version 1.0.1 and earlier, PowerShot SX70 HS firmware version 1.1.0 and earlier, and PowerShot G5Xmark II firmware version 1.0.1 and earlier allows an attacker on the same network segment to trigger the affected product being unresponsive or to execute arbitrary code on the affected product via setadapterbatteryreport command.

Credit: vultures@jpcert.or.jp

Affected SoftwareAffected VersionHow to fix
Canon Eos-1d X Firmware<=2.1.0
Canon Eos-1d X Firmware
Canon Eos-1d X Mkii Firmware<=1.1.6
Canon EOS-1D X Mark II
Canon Eos-1d C Firmware<=1.4.1
Canon Eos-1d C
Canon Eos 5d Mark Iii Firmware<=1.3.5
Canon Eos 5d Mark III
Canon Eos 5d Mark Iv<=1.2.0
Canon Eos 5d Mark Iv
Canon Eos 5ds Firmware<=1.1.2
Canon Eos 5ds R
Canon Eos 5ds R Firmware<=1.1.2
Canon Eos 5ds R
Canon EOS 6D Firmware<=1.1.8
Canon Eos 6d
Canon EOS 7D Mark II<=1.1.2
Canon EOS 7D Mark II
Canon Eos 70d Firmware<=1.1.2
Canon Eos 70d Firmware
Canon Eos 80D Firmware<=1.0.2
Canon Eos 80D Firmware
Canon Eos Kiss X7i Firmware<=1.1.5
Canon Eos Kiss X7i Firmware
Canon Eos D Rebel T5i Firmware<=1.1.5
Canon Eos D Rebel T5i Firmware
Canon Eos 700d Firmware<=1.1.5
Canon Eos 700d Firmware
Canon Eos Kiss X8i Firmware<=1.0.0
Canon Eos Kiss X8i Firmware
Canon Eos D Rebel T6i Firmware<=1.0.0
Canon Eos D Rebel T6i Firmware
Canon Eos 750d Firmware<=1.0.0
Canon Eos 750d Firmware
Canon Eos Kiss X9i<=1.0.1
Canon Eos Kiss X9i
Canon Eos D Rebel T7i<=1.0.1
Canon Eos D Rebel T7i Firmware
Canon Eos 800d Firmware<=1.0.1
Canon Eos 800d Firmware
Canon Eos Kiss X7 Firmware<=1.0.1
Canon Eos Kiss X10 Firmware
Canon Eos D Rebel Sl1 Firmware<=1.0.1
Canon EOS Digital Rebel SL1
Canon Eos 100d Firmware<=1.0.1
Canon Eos 100D
Canon Eos Kiss X9i<=1.0.1
Canon Eos Kiss X9 Firmware
Canon Eos D Rebel SL2<=1.0.1
Canon Eos D Rebel Sl2 Firmware
Canon Eos 200d Firmware<=1.0.1
Canon Eos 200d Firmware
Canon Eos Kiss X10<=1.0.1
Canon Eos Kiss X10 Firmware
Canon Eos D Rebel Sl3 Firmware<=1.0.1
Canon Eos D Rebel Sl3 Firmware
Canon Eos 250d Firmware<=1.0.1
Canon Eos 250d
Canon Eos 8000d Firmware<=1.0.0
Canon Eos 8000d Firmware
Canon Eos D Rebel T6s Firmware<=1.0.0
Canon Eos D Rebel T6s Firmware
Canon Eos 760d Firmware<=1.0.0
Canon Eos 760d Firmware
Canon Eos 9000d Firmware<=1.0.2
Canon EOS 9000D
Canon Eos 77D Firmware<=1.0.2
Canon Eos 77D Firmware
Canon Eos Kiss X70 Firmware<=1.0.2
Canon Eos Kiss X70 Firmware
Canon Eos D Rebel T5 Firmware<=1.0.2
Canon EOS Digital Rebel T5
Canon EOS 1200D MG Firmware<=1.0.2
Canon Eos 1200D
Canon Eos D Rebel T5 Re Firmware<=1.0.2
Canon EOS Digital Rebel T5
Canon EOS 1200D MG Firmware<=1.0.2
Canon Eos 1200D
Canon Eos Hi Firmware<=1.0.2
Canon Eos Hi Firmware
Canon Eos Kiss X80 Firmware<=1.1.0
Canon Eos Kiss X80 Firmware
Canon Eos D Rebel T6 Firmware<=1.1.0
Canon Eos Rebel T6
Canon Eos 1300D Firmware<=1.1.0
Canon Eos 1300D
Canon Eos Kiss X90 Firmware<=1.0.0
Canon Eos Kiss X90
Canon Eos D Rebel T7 Firmware<=1.0.0
Canon EOS Rebel T7
Canon Eos 1500d Firmware<=1.0.0
Canon Eos 1500d Firmware
Canon Eos 2000d Firmware<=1.0.0
Canon Eos 2000d Firmware
Canon Eos D Rebel T100 Firmware<=1.0.0
Canon Eos D Rebel T100
Canon Eos 3000d Firmware<=1.0.0
Canon Eos 3000d Firmware
Canon Eos 4000D Firmware<=1.0.0
Canon Eos 4000D Firmware
Canon Eos R Firmware<=1.3.0
Canon Eos R
Canon Eos Rp Firmware<=1.2.0
Canon EOS RP
Canon Eos Rp Firmware<=1.2.0
Canon EOS RP
Canon Eos M2 Firmware<=1.0.3
Canon Eos M2 Firmware
Canon Eos M3 Firmware<=1.2.0
Canon Eos M3
Canon Eos M5 Firmware<=1.0.1
Canon Eos M5 Firmware
Canon Eos M6 (China) Firmware<=1.0.1
Canon Eos M6 Firmware
Canon Eos M6 (China) Firmware<=5.0.0
Canon EOS M6
Canon Eos M10 Firmware<=1.1.0
Canon Eos M10 Firmware
Canon Eos M100 Firmware<=1.0.0
Canon Eos M100 Firmware
Canon Eos Kiss M Firmware<=1.0.2
Canon Eos Kiss M Firmware
Canon Eos M50 Firmware<=1.0.2
Canon Eos M50 Firmware
Canon Powershot SX740 HS<=1.0.1
Canon Powershot Sx740 Hs Firmware
Canon Powershot SX70 HS Firmware<=1.1.0
Canon Powershot SX70 HS
Canon Powershot G5x Mark II Firmware<=1.0.1
Canon Powershot G5x Mark II Firmware
Canon Eos 6d Mark Ii Firmware<=1.0.4
Canon Eos 6D Mark II

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2019-6001?

    CVE-2019-6001 has a high severity rating due to the potential for a buffer overflow that could lead to arbitrary code execution.

  • How do I fix CVE-2019-6001?

    To fix CVE-2019-6001, update the firmware of your affected Canon EOS digital camera to the latest version available.

  • Which Canon cameras are affected by CVE-2019-6001?

    CVE-2019-6001 affects various Canon EOS cameras including EOS-1D X, EOS-1D X MKII, and EOS 5D MARK III with specific firmware versions.

  • What happens if CVE-2019-6001 is exploited?

    Exploitation of CVE-2019-6001 can enable an attacker to execute arbitrary code on the affected camera, potentially compromising sensitive data.

  • Is there a workaround for CVE-2019-6001?

    Currently, the best workaround for CVE-2019-6001 is to update the firmware on your affected Canon camera to eliminate the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203