HIGH · 7.8

CVE-2019-9210

In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small. (Th...

Vulnerability Description

In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small. (There is also a heap-based buffer over-read.)

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
AdvancemameAdvancecomp2.1
DebianDebian Linux8.0
CanonicalUbuntu Linux14.04
FedoraprojectFedora30

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-9210?

CVE-2019-9210 is a vulnerability with a CVSS score of 7.8 (HIGH). In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small. (Th...

How severe is CVE-2019-9210?

CVE-2019-9210 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-9210?

Check the references section above for vendor advisories and patch information. Affected products include: Advancemame Advancecomp, Debian Debian Linux, Canonical Ubuntu Linux, Fedoraproject Fedora.