CVE-2019-10672Improper Input Validation in Libmysofa

Severity
9.8CRITICALNVD
EPSS
0.6%
top 30.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 31
Latest updateMay 13

Description

treeRead in hdf/btree.c in libmysofa before 0.7 does not properly validate multiplications and additions.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

debiandebian/libmysofa< libmysofa 0.6~dfsg0-3 (bookworm)
Debiansymonics/libmysofa< 0.6~dfsg0-3+3
Ubuntufasterxml/jackson-databind< 2.4.2-3ubuntu0.1~esm2

Patches

🔴Vulnerability Details

3
GHSA
GHSA-2xrc-jfhx-ghwr: treeRead in hdf/btree2022-05-13
OSV
jackson-databind vulnerabilities2021-03-15
OSV
CVE-2019-10672: treeRead in hdf/btree2019-03-31

📋Vendor Advisories

2
Ubuntu
libmysofa vulnerability2019-06-24
Debian
CVE-2019-10672: libmysofa - treeRead in hdf/btree.c in libmysofa before 0.7 does not properly validate multi...2019
CVE-2019-10672 — Improper Input Validation in Libmysofa | cvebase