Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-5086

Опубликовано: 21 нояб. 2019
Источник: ubuntu
Приоритет: medium
CVSS2: 6.8
CVSS3: 8.8

Описание

An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools, version 1.0.7. An integer overflow can occur while walking through tiles that could be exploited to corrupt memory and execute arbitrary code. In order to trigger this vulnerability, a victim would need to open a specially crafted XCF file.

РелизСтатусПримечание
bionic

released

1.0.7-6ubuntu0.1
devel

DNE

disco

ignored

end of life
eoan

ignored

end of life
esm-apps/bionic

released

1.0.7-6ubuntu0.1
esm-apps/focal

released

1.0.7-6ubuntu0.20.04.1
esm-apps/xenial

released

1.0.7-5ubuntu0.1~esm1
esm-infra-legacy/trusty

DNE

focal

released

1.0.7-6ubuntu0.20.04.1
groovy

ignored

end of life

Показывать по

6.8 Medium

CVSS2

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
около 6 лет назад

An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools, version 1.0.7. An integer overflow can occur while walking through tiles that could be exploited to corrupt memory and execute arbitrary code. In order to trigger this vulnerability, a victim would need to open a specially crafted XCF file.

CVSS3: 8.8
debian
около 6 лет назад

An exploitable integer overflow vulnerability exists in the flattenInc ...

CVSS3: 8.8
github
больше 3 лет назад

An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools, version 1.0.7. An integer overflow can occur while walking through tiles that could be exploited to corrupt memory and execute arbitrary code. In order to trigger this vulnerability, a victim would need to open a specially crafted XCF file.

6.8 Medium

CVSS2

8.8 High

CVSS3