Resource management error in Exiv2 - CVE-2019-13112
Published: August 19, 2019
Vulnerability identifier: #VU20307
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13112
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform denial of service (DoS) attack.
The vulnerability exists due to memory allocation error in PngChunk::parseChunkContent() function. A remote attacker can create a specially crafted PNG image, pass it to the application and perform a denial of service attack.
Affected software
Exiv2
exiv2 (Alpine package)
exiv2-debuginfo
exiv2-debugsource
libexiv2-12
libexiv2-12-debuginfo
libexiv2-devel
exiv2
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
Fedora
exiv2 (Alpine package)
exiv2-debuginfo
exiv2-debugsource
libexiv2-12
libexiv2-12-debuginfo
libexiv2-devel
exiv2
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
Fedora
How to mitigate CVE-2019-13112
Install updates from vendor's website.
Exiv2 - update to 0.27.2
exiv2 (Alpine package) - update to 0.27.2-r0
exiv2-debuginfo - update to 0.23-12.18.1
exiv2-debugsource - update to 0.23-12.18.1
libexiv2-12 - update to 0.23-12.18.1
libexiv2-12-debuginfo - update to 0.23-12.18.1
libexiv2-devel - update to 0.23-12.18.1
exiv2 - update to 0.27.2-1.fc30
exiv2 (Alpine package) - update to 0.27.2-r0
exiv2-debuginfo - update to 0.23-12.18.1
exiv2-debugsource - update to 0.23-12.18.1
libexiv2-12 - update to 0.23-12.18.1
libexiv2-12-debuginfo - update to 0.23-12.18.1
libexiv2-devel - update to 0.23-12.18.1
exiv2 - update to 0.27.2-1.fc30