Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-5086

Опубликовано: 21 нояб. 2019
Источник: nvd
CVSS3: 7.5
CVSS3: 8.8
CVSS2: 6.8
EPSS Низкий

Описание

An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools, version 1.0.7. An integer overflow can occur while walking through tiles that could be exploited to corrupt memory and execute arbitrary code. In order to trigger this vulnerability, a victim would need to open a specially crafted XCF file.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:xcftools_project:xcftools:1.0.7:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

EPSS

Процентиль: 42%
0.00203
Низкий

7.5 High

CVSS3

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-680
CWE-190

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 6 лет назад

An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools, version 1.0.7. An integer overflow can occur while walking through tiles that could be exploited to corrupt memory and execute arbitrary code. In order to trigger this vulnerability, a victim would need to open a specially crafted XCF file.

CVSS3: 8.8
debian
около 6 лет назад

An exploitable integer overflow vulnerability exists in the flattenInc ...

CVSS3: 8.8
github
больше 3 лет назад

An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools, version 1.0.7. An integer overflow can occur while walking through tiles that could be exploited to corrupt memory and execute arbitrary code. In order to trigger this vulnerability, a victim would need to open a specially crafted XCF file.

EPSS

Процентиль: 42%
0.00203
Низкий

7.5 High

CVSS3

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-680
CWE-190