Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-6976

Опубликовано: 26 янв. 2019
Источник: debian
EPSS Низкий

Описание

libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c does not zero out allocated memory. This can result in leaking raw process memory contents through the output image.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
vipsfixed8.7.4-1package
vipsfixed8.4.5-1+deb9u1stretchpackage
vipsignoredjessiepackage

Примечания

  • https://github.com/libvips/libvips/commit/00622428bda8d7521db8d74260b519fa41d69d0a

EPSS

Процентиль: 64%
0.00475
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 7 лет назад

libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c does not zero out allocated memory. This can result in leaking raw process memory contents through the output image.

CVSS3: 5.3
nvd
около 7 лет назад

libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c does not zero out allocated memory. This can result in leaking raw process memory contents through the output image.

CVSS3: 5.3
github
больше 3 лет назад

libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c does not zero out allocated memory. This can result in leaking raw process memory contents through the output image.

EPSS

Процентиль: 64%
0.00475
Низкий