Integer overflow in autotrace - CVE-2019-19004
Published: August 6, 2024
Vulnerability identifier: #VU95413
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-19004
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to integer overflow in input-bmp.c. A remote attacker can trick the victim to pass specially crafted input to the application, trigger an integer overflow and crash the application.
Affected software
autotrace
Amazon Linux AMI
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Fedora
autotrace (Red Hat package)
autotrace
Amazon Linux AMI
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Fedora
autotrace (Red Hat package)
autotrace
How to mitigate CVE-2019-19004
Install updates from vendor's website.
autotrace - update to 0.31.9
autotrace (Red Hat package) - update to 0.31.1-53.el8
autotrace - update to 0.31.1-60.fc34
autotrace - update to 0.31.1-62
autotrace (Red Hat package) - update to 0.31.1-53.el8
autotrace - update to 0.31.1-60.fc34
autotrace - update to 0.31.1-62