Resource management error in Exiv2 - CVE-2019-13112

 

Resource management error in Exiv2 - CVE-2019-13112

Published: August 19, 2019


Vulnerability identifier: #VU20307
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13112
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform denial of service (DoS) attack.

The vulnerability exists due to memory allocation error in PngChunk::parseChunkContent() function. A remote attacker can create a specially crafted PNG image, pass it to the application and perform a denial of service attack.


Affected software

Exiv2
exiv2 (Alpine package)
exiv2-debuginfo
exiv2-debugsource
libexiv2-12
libexiv2-12-debuginfo
libexiv2-devel
exiv2
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
Fedora

How to mitigate CVE-2019-13112

Install updates from vendor's website.

Exiv2 - update to 0.27.2
exiv2 (Alpine package) - update to 0.27.2-r0
exiv2-debuginfo - update to 0.23-12.18.1
exiv2-debugsource - update to 0.23-12.18.1
libexiv2-12 - update to 0.23-12.18.1
libexiv2-12-debuginfo - update to 0.23-12.18.1
libexiv2-devel - update to 0.23-12.18.1
exiv2 - update to 0.27.2-1.fc30

External References

Related Security Bulletins