Out-of-bounds read in Debian Linux - CVE-2018-19535

 

Out-of-bounds read in Debian Linux - CVE-2018-19535

Published: November 26, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU36389
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-19535
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

In Exiv2 0.26 and previous versions, PngChunk::readRawProfile in pngchunk_int.cpp may cause a denial of service (application crash due to a heap-based buffer over-read) via a crafted PNG file.


Affected software

Debian Linux
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
exiv2-debugsource
libexiv2-devel
exiv2-debuginfo
libexiv2-12-debuginfo
libexiv2-12

How to mitigate CVE-2018-19535

Install update from vendor's website.

exiv2-debugsource - update to 0.23-12.21.1
libexiv2-devel - update to 0.23-12.21.1
exiv2-debuginfo - update to 0.23-12.21.1
libexiv2-12-debuginfo - update to 0.23-12.21.1
libexiv2-12 - update to 0.23-12.21.1

External References

Related Security Bulletins