CVE-2019-6976
Summary
| CVE | CVE-2019-6976 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-01-26 23:29:00 UTC |
| Updated | 2023-09-29 11:18:00 UTC |
| Description | libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c does not zero out allocated memory. This can result in leaking raw process memory contents through the output image. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| zero memory on malloc · libvips/libvips@0062242 · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| Release v8.7.4 · libvips/libvips · GitHub |
MISC |
github.com |
Third Party Advisory |
| Drop-by-Drop: Bleeding through libvips – Silent Signal Techblog |
MISC |
blog.silentsignal.eu |
Technical Description, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 199837 Ubuntu Security Notification for VIPS Vulnerabilities (USN-6437-1)