MEDIUM · 5.5

CVE-2019-11459

The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to un...

Vulnerability Description

The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
GnomeEvince<= 3.32.0
CanonicalUbuntu Linux16.04
FedoraprojectFedora29
DebianDebian Linux8.0
RedhatEnterprise Linux8.0
RedhatEnterprise Linux Eus8.1
RedhatEnterprise Linux Server Aus8.2
RedhatEnterprise Linux Server Tus8.2
OpensuseLeap15.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-11459?

CVE-2019-11459 is a vulnerability with a CVSS score of 5.5 (MEDIUM). The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to un...

How severe is CVE-2019-11459?

CVE-2019-11459 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-11459?

Check the references section above for vendor advisories and patch information. Affected products include: Gnome Evince, Canonical Ubuntu Linux, Fedoraproject Fedora, Debian Debian Linux, Redhat Enterprise Linux.