{"api_version":"1","generated_at":"2026-07-23T08:58:45+00:00","cve":"CVE-2019-5086","urls":{"html":"https://cve.report/CVE-2019-5086","api":"https://cve.report/api/cve/CVE-2019-5086.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-5086","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-5086"},"summary":{"title":"CVE-2019-5086","description":"An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools, version 1.0.7. An integer overflow can occur while walking through tiles that could be exploited to corrupt memory and execute arbitrary code. In order to trigger this vulnerability, a victim would need to open a specially crafted XCF file.","state":"PUBLIC","assigner":"talos-cna@cisco.com","published_at":"2019-11-21 16:15:00","updated_at":"2022-06-21 19:22:00"},"problem_types":["CWE-787","CWE-190"],"metrics":[],"references":[{"url":"https://lists.debian.org/debian-lts-announce/2021/02/msg00014.html","name":"[debian-lts-announce] 20210210 [SECURITY] [DLA 2553-1] xcftools security update","refsource":"MLIST","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] [DLA 2553-1] xcftools security update","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0878","name":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0878","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"TALOS-2019-0878 ||  Cisco Talos Intelligence Group - Comprehensive Threat Intelligence","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://talosintelligence.com/vulnerability_reports/TALOS-2019-0878","name":"https://talosintelligence.com/vulnerability_reports/TALOS-2019-0878","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"TALOS-2019-0878 ||  Cisco Talos Intelligence Group - Comprehensive Threat Intelligence","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2021/03/msg00008.html","name":"[debian-lts-announce] 20210308 [SECURITY] [DLA 2553-2] xcftools regression update","refsource":"MLIST","tags":[],"title":"[SECURITY] [DLA 2553-2] xcftools regression update","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-5086","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-5086","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"5086","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"5086","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"5086","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xcftools_project","cpe5":"xcftools","cpe6":"1.0.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"5086","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xcftools_project","cpe5":"xcftools","cpe6":"1.0.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2019-5086","qid":"199266","title":"Ubuntu Security Notification for Xcftools Vulnerabilities (USN-5988-1)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-5086","ASSIGNER":"talos-cna@cisco.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"xcftools","version":{"version_data":[{"version_value":"xcftools 1.0.7"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-680: Integer Overflow to Buffer Overflow"}]}]},"references":{"reference_data":[{"refsource":"MLIST","name":"[debian-lts-announce] 20210210 [SECURITY] [DLA 2553-1] xcftools security update","url":"https://lists.debian.org/debian-lts-announce/2021/02/msg00014.html"},{"refsource":"MLIST","name":"[debian-lts-announce] 20210308 [SECURITY] [DLA 2553-2] xcftools regression update","url":"https://lists.debian.org/debian-lts-announce/2021/03/msg00008.html"},{"refsource":"MISC","name":"https://talosintelligence.com/vulnerability_reports/TALOS-2019-0878","url":"https://talosintelligence.com/vulnerability_reports/TALOS-2019-0878"},{"refsource":"MISC","name":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0878","url":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0878"}]},"description":{"description_data":[{"lang":"eng","value":"An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools, version 1.0.7. An integer overflow can occur while walking through tiles that could be exploited to corrupt memory and execute arbitrary code. In order to trigger this vulnerability, a victim would need to open a specially crafted XCF file."}]},"impact":{"cvss":{"baseScore":7.5,"baseSeverity":"High","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.0"}}},"nvd":{"publishedDate":"2019-11-21 16:15:00","lastModifiedDate":"2022-06-21 19:22:00","problem_types":["CWE-787","CWE-190"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:xcftools_project:xcftools:1.0.7:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"5086","Ordinal":"142702","Title":"CVE-2019-5086","CVE":"CVE-2019-5086","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"5086","Ordinal":"1","NoteData":"An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools, version 1.0.7. An integer overflow can occur while walking through tiles that could be exploited to corrupt memory and execute arbitrary code. In order to trigger this vulnerability, a victim would need to open a specially crafted XCF file.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"5086","Ordinal":"2","NoteData":"2019-11-21","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"5086","Ordinal":"3","NoteData":"2021-03-08","Type":"Other","Title":"Modified"}]}}}