Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-6976

Опубликовано: 26 янв. 2019
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c does not zero out allocated memory. This can result in leaking raw process memory contents through the output image.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:libvips:libvips:*:*:*:*:*:*:*:*
Версия до 8.7.4 (исключая)

EPSS

Процентиль: 64%
0.00475
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-908

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 7 лет назад

libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c does not zero out allocated memory. This can result in leaking raw process memory contents through the output image.

CVSS3: 5.3
debian
около 7 лет назад

libvips before 8.7.4 generates output images from uninitialized memory ...

CVSS3: 5.3
github
больше 3 лет назад

libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c does not zero out allocated memory. This can result in leaking raw process memory contents through the output image.

EPSS

Процентиль: 64%
0.00475
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-908