CVE-2019-11459
published 2019-04-22CVE-2019-11459: The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from…
PriorityP422medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
1.44%
70.3th percentile
The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | atril | < atril 1.22.3-1 (bookworm) | atril 1.22.3-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | evince | < atril 1.22.3-1 (bookworm) | atril 1.22.3-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnome | evince | <= 3.32.0 | — |
| gnome | evince | >= 0 < 3.32.0-3 | 3.32.0-3 |
| gnome | evince | >= 0 < 3.32.0-3 | 3.32.0-3 |
| gnome | evince | >= 0 < 3.32.0-3 | 3.32.0-3 |
| gnome | evince | >= 0 < 3.32.0-3 | 3.32.0-3 |
| mate-desktop | atril | >= 0 < 1.22.3-1 | 1.22.3-1 |
| mate-desktop | atril | >= 0 < 1.22.3-1 | 1.22.3-1 |
| mate-desktop | atril | >= 0 < 1.22.3-1 | 1.22.3-1 |
| mate-desktop | atril | >= 0 < 1.22.3-1 | 1.22.3-1 |
| mate-desktop | atril | >= 0 < 1.24.0-1ubuntu0.2 | 1.24.0-1ubuntu0.2 |
| mate-desktop | atril | >= 0 < 1.26.0-1ubuntu1.2 | 1.26.0-1ubuntu1.2 |
| mate-desktop | atril | >= 0 < 1.20.1-2ubuntu2+esm2 | 1.20.1-2ubuntu2+esm2 |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
atril vulnerabilities
osv·2025-02-18·CVSS 7.8
CVE-2019-1010006 [HIGH] atril vulnerabilities
atril vulnerabilities
It was discovered that Atril incorrectly handled certain PDF files.
An attacker could possibly use this issue to cause a denial of service
or to execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2019-1010006)
Andy Nguyen discovered that Atril incorrectly handled certain images. An
attacker could possibly use this issue to expose sensitive information.
This issue only affected Ubuntu 16.04 LTS. (CVE-2019-11459)
Febin Mon Saji discovered that Atril incorrectly handled certain
compressed files. A remote attacker could possibly use this issue to
cause a denial of service or to execute arbitrary code. (CVE-2023-51698)
GHSA
GHSA-3q2g-r99g-8h69: The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3
ghsa_unreviewed·2022-05-24
CVE-2019-11459 [MEDIUM] CWE-754 GHSA-3q2g-r99g-8h69: The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3
The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.
OSV
CVE-2019-11459: The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3
osv·2019-04-22·CVSS 5.5
CVE-2019-11459 [MEDIUM] CVE-2019-11459: The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3
The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.
Ubuntu
Atril vulnerabilities
vendor_ubuntu·2025-02-18·CVSS 7.8
CVE-2023-51698 [HIGH] Atril vulnerabilities
Title: Atril vulnerabilities
Summary: Atril could be made to crash or run programs as your login if it
opened a specially crafted file.
It was discovered that Atril incorrectly handled certain PDF files.
An attacker could possibly use this issue to cause a denial of service
or to execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2019-1010006)
Andy Nguyen discovered that Atril incorrectly handled certain images. An
attacker could possibly use this issue to expose sensitive information.
This issue only affected Ubuntu 16.04 LTS. (CVE-2019-11459)
Febin Mon Saji discovered that Atril incorrectly handled certain
compressed files. A remote attacker could possibly use this issue to
cause a denial of service or to execute arbitrary code. (CVE-2023-51698)
Instructions: In
Ubuntu
Evince vulnerability
vendor_ubuntu·2019-04-29
CVE-2019-11459 Evince vulnerability
Title: Evince vulnerability
Summary: Evince could be made to expose sensitive information if it received
a specially crafted file.
It was discovered that Evince incorrectly handled certain images.
An attacker could possibly use this issue to expose sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
evince: uninitialized memory use in function tiff_document_render() and tiff_document_get_thumbnail()
vendor_redhat·2019-04-13·CVSS 5.5
CVE-2019-11459 [MEDIUM] CWE-125 evince: uninitialized memory use in function tiff_document_render() and tiff_document_get_thumbnail()
evince: uninitialized memory use in function tiff_document_render() and tiff_document_get_thumbnail()
The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.
Statement: This issue affects the versions of evince as shipped with Red Hat Enterprise Linux 5, 6, 7, and 8.
Red Hat Enterprise Linux 5 is now in Extended Life Phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
Red Hat Enterp
Debian
CVE-2019-11459: atril - The tiff_document_render() and tiff_document_get_thumbnail() functions in the TI...
vendor_debian·2019·CVSS 5.5
CVE-2019-11459 [MEDIUM] CVE-2019-11459: atril - The tiff_document_render() and tiff_document_get_thumbnail() functions in the TI...
The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.
Scope: local
bookworm: resolved (fixed in 1.22.3-1)
bullseye: resolved (fixed in 1.22.3-1)
forky: resolved (fixed in 1.22.3-1)
sid: resolved (fixed in 1.22.3-1)
trixie: resolved (fixed in 1.22.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-11459 evince: uninitialized memory use in function tiff_document_render() and tiff_document_get_thumbnail()
bugzilla·2019-06-03·CVSS 5.5
CVE-2019-11459 [MEDIUM] CVE-2019-11459 evince: uninitialized memory use in function tiff_document_render() and tiff_document_get_thumbnail()
CVE-2019-11459 evince: uninitialized memory use in function tiff_document_render() and tiff_document_get_thumbnail()
The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.
Reference:
https://gitlab.gnome.org/GNOME/evince/issues/1129
Discussion:
Created evince tracking bugs for this issue:
Affects: fedora-29 [bug 1716298]
---
Created evince tracking bugs for this issue:
Affects: fedora-30 [bug 1716299]
---
Patch:
https://gitlab.gnome.org/GNOME/evince/commit/234f034a4d15cd46dd556f4945f99fbd57ef5f15
---
Statement:
This issue affects the versions of evince as shipped with Re
Bugzilla
CVE-2019-11459 evince: uninitialized memory use in function tiff_document_render() and tiff_document_get_thumbnail() [fedora-30]
bugzilla·2019-06-03·CVSS 5.5
CVE-2019-11459 [MEDIUM] CVE-2019-11459 evince: uninitialized memory use in function tiff_document_render() and tiff_document_get_thumbnail() [fedora-30]
CVE-2019-11459 evince: uninitialized memory use in function tiff_document_render() and tiff_document_get_thumbnail() [fedora-30]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-30.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
D
Bugzilla
CVE-2019-11459 evince: uninitialized memory use in function tiff_document_render() and tiff_document_get_thumbnail() [fedora-29]
bugzilla·2019-06-03·CVSS 5.5
CVE-2019-11459 [MEDIUM] CVE-2019-11459 evince: uninitialized memory use in function tiff_document_render() and tiff_document_get_thumbnail() [fedora-29]
CVE-2019-11459 evince: uninitialized memory use in function tiff_document_render() and tiff_document_get_thumbnail() [fedora-29]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-29.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
D
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00089.htmlhttps://access.redhat.com/errata/RHSA-2019:3553https://gitlab.gnome.org/GNOME/evince/issues/1129https://lists.debian.org/debian-lts-announce/2019/08/msg00013.htmlhttps://lists.debian.org/debian-lts-announce/2019/08/msg00014.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7LU4YZK5S46TZAH4J3NYYUYFMOC47LJG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YJ6R7NMY44IHIQIY24CV3WV2GLGJPQPZ/https://seclists.org/bugtraq/2020/Feb/18https://usn.ubuntu.com/3959-1/https://www.debian.org/security/2020/dsa-4624http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00089.htmlhttps://access.redhat.com/errata/RHSA-2019:3553https://gitlab.gnome.org/GNOME/evince/issues/1129https://lists.debian.org/debian-lts-announce/2019/08/msg00013.htmlhttps://lists.debian.org/debian-lts-announce/2019/08/msg00014.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7LU4YZK5S46TZAH4J3NYYUYFMOC47LJG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YJ6R7NMY44IHIQIY24CV3WV2GLGJPQPZ/https://seclists.org/bugtraq/2020/Feb/18https://usn.ubuntu.com/3959-1/https://www.debian.org/security/2020/dsa-4624
2019-04-22
Published