UBUNTU-CVE-2019-6976
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-6976
UBUNTU-CVE-2019-6976
Summary:
Details: libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c does not zero out allocated memory. This can result in leaking raw process memory contents through the output image.
References: https://ubuntu.com/security/CVE-2019-6976, https://blog.silentsignal.eu/2019/04/18/drop-by-drop-bleeding-through-libvips/, https://github.com/libvips/libvips/commit/00622428bda8d7521db8d74260b519fa41d69d0a, https://github.com/libvips/libvips/releases/tag/v8.7.4, https://ubuntu.com/security/notices/USN-6437-1, https://www.cve.org/CVERecord?id=CVE-2019-6976
Affected packages
Package
Name: vips
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
