CVE-2019-9656: Null Pointer Dereference
Published Mar 11, 2019
·Updated
An issue was discovered in LibOFX 0.9.14. There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofxsgml.cpp, as demonstrated by ofxdump.
Affected Software
4 affected componentsFixes available
debian/libofx
1:0.9.15-31:0.10.9-11:0.10.9-1.1
Libofx Project Libofx=0.9.14
Debian Debian Linux=8.0
Canonical Ubuntu Linux=16.04
Event History
Mar 11, 2019
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Aug 8, 2024
Data Sourced
via Launchpad·10:03 PM
Description
Feb 23, 2026
Data Sourced
via Ubuntu·05:42 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-9656?
CVE-2019-9656 has been classified as a medium severity vulnerability due to potential impact from a NULL pointer dereference.
2
How do I fix CVE-2019-9656?
To address CVE-2019-9656, upgrade to LibOFX version 0.9.15-3 or later.
3
What software is affected by CVE-2019-9656?
CVE-2019-9656 affects LibOFX version 0.9.14 and also impacts Debian and Ubuntu systems that utilize this version.
4
Is CVE-2019-9656 a remote or local vulnerability?
CVE-2019-9656 is considered a local vulnerability, as it requires local access to be exploited.
5
What functions are impacted in CVE-2019-9656?
CVE-2019-9656 specifically impacts the function OFXApplication::startElement in lib/ofx_sgml.cpp.