CVE-2019-1010006
Summary
| CVE | CVE-2019-1010006 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-15 02:15:00 UTC |
| Updated | 2024-02-02 03:07:00 UTC |
| Description | Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The component is: backend/tiff/tiff-document.c. The attack vector is: Victim must open a crafted PDF file. The issue occurs because of an incorrect integer overflow protection mechanism in tiff_document_render and tiff_document_get_thumbnail. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| USN-4067-1: Evince vulnerability | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
|
| Bug 2745 – Multiple out of bound write |
MISC |
bugzilla.maptools.org |
Exploit, Issue Tracking, Third Party Advisory |
| Bugtraq: [SECURITY] [DSA 4624-1] evince security update |
BUGTRAQ |
seclists.org |
|
| [SECURITY] [DLA 1881-1] evince security update |
MLIST |
lists.debian.org |
|
| Debian -- Security Information -- DSA-4624-1 evince |
DEBIAN |
www.debian.org |
|
| [security-announce] openSUSE-SU-2019:1908-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| Bug 788980 – Multiple out of bound write and segfault |
MISC |
bugzilla.gnome.org |
Exploit, Issue Tracking, Third Party Advisory |
| [SECURITY] [DLA 1882-1] atril security update |
MLIST |
lists.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 670298 EulerOS Security Update for evince (EulerOS-SA-2021-1778)
- 670608 EulerOS Security Update for evince (EulerOS-SA-2021-2366)