Access of Uninitialized Pointer in Evince - CVE-2019-11459

 

Access of Uninitialized Pointer in Evince - CVE-2019-11459

Published: June 25, 2020


Vulnerability identifier: #VU29244
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11459
CWE-ID: CWE-824
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due tothe TIFFReadRGBAImageOriented() function called from tiff_document_render() and tiff_document_get_thumbnail() functions in the backend/tiff/tiff-document.c in GNOME Evince returns uninitialized memory instead of false, when failing to read an image. A remote attacker can gain access to sensitive information on the system.


Affected software

Evince
Debian Linux
Amazon Linux AMI
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Ubuntu
openEuler
Fedora
evince (Alpine package)
atril (Ubuntu package)
atril-common (Ubuntu package)
libatrildocument3 (Ubuntu package)
evince
gnome-remote-desktop (Red Hat package)
accountsservice (Red Hat package)
plymouth (Red Hat package)
poppler (Red Hat package)
SDL (Red Hat package)
wayland-protocols (Red Hat package)
gvfs (Red Hat package)
pango (Red Hat package)
gjs (Red Hat package)
pidgin (Red Hat package)
webkit2gtk3 (Red Hat package)
gdk-pixbuf2 (Red Hat package)
evince (Debian package)
gtk3 (Red Hat package)
baobab (Red Hat package)
file-roller (Red Hat package)
gnome-tweaks (Red Hat package)
nautilus (Red Hat package)
gnome-control-center (Red Hat package)
evince (Red Hat package)
gdm (Red Hat package)
evince-help
evince-debuginfo
evince-devel
evince-debugsource
gnome-software (Red Hat package)
gsettings-desktop-schemas (Red Hat package)
gnome-settings-daemon (Red Hat package)
gnome-shell-extensions (Red Hat package)
gnome-desktop3 (Red Hat package)
gnome-shell (Red Hat package)
mutter (Red Hat package)
appstream-data (Red Hat package)
chrome-gnome-shell (Red Hat package)
mozjs60 (Red Hat package)

How to mitigate CVE-2019-11459

Install updates from vendor's website.

Evince - update to 3.32.1
atril (Ubuntu package) - addressed in versions Ubuntu Pro, 1.24.0-1ubuntu0.2, 1.26.0-1ubuntu1.2
atril-common (Ubuntu package) - addressed in versions Ubuntu Pro, 1.24.0-1ubuntu0.2, 1.26.0-1ubuntu1.2
libatrildocument3 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.24.0-1ubuntu0.2, 1.26.0-1ubuntu1.2
evince - addressed in versions master-3020190614123051.1, 3.30.2-4.fc29, 3.32.0-3.fc30
gnome-remote-desktop (Red Hat package) - update to 0.1.6-5.el8
accountsservice (Red Hat package) - update to 0.6.50-7.el8
plymouth (Red Hat package) - update to 0.9.3-15.el8
poppler (Red Hat package) - update to 0.26.5-42.el7
SDL (Red Hat package) - update to 1.2.15-35.el8
wayland-protocols (Red Hat package) - update to 1.17-1.el8
gvfs (Red Hat package) - update to 1.36.2-6.el8
pango (Red Hat package) - update to 1.42.4-6.el8
gjs (Red Hat package) - update to 1.56.2-3.el8
pidgin (Red Hat package) - update to 2.13.0-5.el8
webkit2gtk3 (Red Hat package) - update to 2.24.3-1.el8
gdk-pixbuf2 (Red Hat package) - update to 2.36.12-5.el8
evince (Debian package) - addressed in versions 3.22.1-3+deb9u2, 3.30.2-3+deb10u1
gtk3 (Red Hat package) - update to 3.22.30-4.el8
baobab (Red Hat package) - update to 3.28.0-2.el8
file-roller (Red Hat package) - update to 3.28.1-2.el8
gnome-tweaks (Red Hat package) - update to 3.28.1-6.el8
nautilus (Red Hat package) - update to 3.28.1-10.el8
gnome-control-center (Red Hat package) - update to 3.28.2-5.el8
evince (Red Hat package) - addressed in versions 3.28.2-9.el7, 3.28.4-3.el8
gdm (Red Hat package) - update to 3.28.3-22.el8
evince - update to 3.30.1-4
evince-help - update to 3.30.1-4
evince-debuginfo - update to 3.30.1-4
evince-devel - update to 3.30.1-4
evince-debugsource - update to 3.30.1-4
gnome-software (Red Hat package) - update to 3.30.6-2.el8
gsettings-desktop-schemas (Red Hat package) - update to 3.32.0-3.el8
gnome-settings-daemon (Red Hat package) - update to 3.32.0-4.el8
gnome-shell-extensions (Red Hat package) - update to 3.32.1-10.el8
gnome-desktop3 (Red Hat package) - update to 3.32.2-1.el8
gnome-shell (Red Hat package) - update to 3.32.2-9.el8
mutter (Red Hat package) - update to 3.32.2-10.el8
appstream-data (Red Hat package) - update to 8-20190805.el8
chrome-gnome-shell (Red Hat package) - update to 10.1-6.el8
mozjs60 (Red Hat package) - update to 60.9.0-3.el8

External References

Related Security Bulletins