cbcvebase.
CVE-2019-11459
published 2019-04-22

CVE-2019-11459: The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from…

PriorityP422medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
1.44%
70.3th percentile
The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianatril< atril 1.22.3-1 (bookworm)atril 1.22.3-1 (bookworm)
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianevince< atril 1.22.3-1 (bookworm)atril 1.22.3-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
gnomeevince<= 3.32.0
gnomeevince>= 0 < 3.32.0-33.32.0-3
gnomeevince>= 0 < 3.32.0-33.32.0-3
gnomeevince>= 0 < 3.32.0-33.32.0-3
gnomeevince>= 0 < 3.32.0-33.32.0-3
mate-desktopatril>= 0 < 1.22.3-11.22.3-1
mate-desktopatril>= 0 < 1.22.3-11.22.3-1
mate-desktopatril>= 0 < 1.22.3-11.22.3-1
mate-desktopatril>= 0 < 1.22.3-11.22.3-1
mate-desktopatril>= 0 < 1.24.0-1ubuntu0.21.24.0-1ubuntu0.2
mate-desktopatril>= 0 < 1.26.0-1ubuntu1.21.26.0-1ubuntu1.2
mate-desktopatril>= 0 < 1.20.1-2ubuntu2+esm21.20.1-2ubuntu2+esm2
opensuseleap
opensuseleap

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.