CVE-2019-17533
published 2019-10-13CVE-2019-17533: Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read in strdup_vprintf when uninitialized…
PriorityP339high8.2CVSS 3.1
AVNACLPRNUINSUCLINAH
EPSS
1.90%
77.3th percentile
Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read in strdup_vprintf when uninitialized memory is accessed.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libmatio | < libmatio 1.5.17-4 (bookworm) | libmatio 1.5.17-4 (bookworm) |
| matio_project | matio | — | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv8.2HIGH
vendor_debian8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5pj8-j8jm-vm7w: Mat_VarReadNextInfo4 in mat4
ghsa_unreviewed·2022-05-24
CVE-2019-17533 [MEDIUM] CWE-125 GHSA-5pj8-j8jm-vm7w: Mat_VarReadNextInfo4 in mat4
Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read in strdup_vprintf when uninitialized memory is accessed.
OSV
CVE-2019-17533: Mat_VarReadNextInfo4 in mat4
osv·2019-10-13·CVSS 8.2
CVE-2019-17533 [HIGH] CVE-2019-17533: Mat_VarReadNextInfo4 in mat4
Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read in strdup_vprintf when uninitialized memory is accessed.
Ubuntu
MATIO vulnerability
vendor_ubuntu·2022-08-10
CVE-2019-17533 MATIO vulnerability
Title: MATIO vulnerability
Summary: MATIO could be made to crash if it received specially crafted
input.
It was discovered that MATIO incorrectly handled certain inputs. An
attacker could possibly use this issue to cause a denial of service or
obtain sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-17533: libmatio - Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, l...
vendor_debian·2019·CVSS 8.2
CVE-2019-17533 [HIGH] CVE-2019-17533: libmatio - Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, l...
Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read in strdup_vprintf when uninitialized memory is accessed.
Scope: local
bookworm: resolved (fixed in 1.5.17-4)
bullseye: resolved (fixed in 1.5.17-4)
forky: resolved (fixed in 1.5.17-4)
sid: resolved (fixed in 1.5.17-4)
trixie: resolved (fixed in 1.5.17-4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-17533 matio: improper null termination in Mat_VarReadNextInfo4 in mat4.c leads to heap-based overflow [fedora-all]
bugzilla·2019-11-06·CVSS 8.2
CVE-2019-17533 [HIGH] CVE-2019-17533 matio: improper null termination in Mat_VarReadNextInfo4 in mat4.c leads to heap-based overflow [fedora-all]
CVE-2019-17533 matio: improper null termination in Mat_VarReadNextInfo4 in mat4.c leads to heap-based overflow [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE:
Bugzilla
CVE-2019-17533 matio: improper null termination in Mat_VarReadNextInfo4 in mat4.c leads to heap-based overflow
bugzilla·2019-11-06·CVSS 8.2
CVE-2019-17533 [HIGH] CVE-2019-17533 matio: improper null termination in Mat_VarReadNextInfo4 in mat4.c leads to heap-based overflow
CVE-2019-17533 matio: improper null termination in Mat_VarReadNextInfo4 in mat4.c leads to heap-based overflow
Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read in strdup_vprintf when uninitialized memory is accessed.
References:
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16856
https://github.com/tbeu/matio/commit/651a8e28099edb5fbb9e4e1d4d3238848f446c9a
Discussion:
Created matio tracking bugs for this issue:
Affects: epel-6 [bug 1769547]
Affects: epel-7 [bug 1769548]
---
Created matio tracking bugs for this issue:
Affects: fedora-all [bug 1769550]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat produ
Bugzilla
CVE-2019-17533 matio: improper null termination in Mat_VarReadNextInfo4 in mat4.c leads to heap-based overflow [epel-7]
bugzilla·2019-11-06·CVSS 8.2
CVE-2019-17533 [HIGH] CVE-2019-17533 matio: improper null termination in Mat_VarReadNextInfo4 in mat4.c leads to heap-based overflow [epel-7]
CVE-2019-17533 matio: improper null termination in Mat_VarReadNextInfo4 in mat4.c leads to heap-based overflow [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
U
Bugzilla
CVE-2019-17533 matio: improper null termination in Mat_VarReadNextInfo4 in mat4.c leads to heap-based overflow [epel-6]
bugzilla·2019-11-06·CVSS 8.2
CVE-2019-17533 [HIGH] CVE-2019-17533 matio: improper null termination in Mat_VarReadNextInfo4 in mat4.c leads to heap-based overflow [epel-6]
CVE-2019-17533 matio: improper null termination in Mat_VarReadNextInfo4 in mat4.c leads to heap-based overflow [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
U
Bugzilla
CVE-2019-17533 matio: improper null termination in Mat_VarReadNextInfo4 in mat4.c leads to heap-based overflow [fedora-all]
bugzilla·2019-11-06·CVSS 8.2
CVE-2019-17533 [HIGH] CVE-2019-17533 matio: improper null termination in Mat_VarReadNextInfo4 in mat4.c leads to heap-based overflow [fedora-all]
CVE-2019-17533 matio: improper null termination in Mat_VarReadNextInfo4 in mat4.c leads to heap-based overflow [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE:
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16856https://github.com/tbeu/matio/commit/651a8e28099edb5fbb9e4e1d4d3238848f446c9ahttps://lists.debian.org/debian-lts-announce/2020/06/msg00037.htmlhttps://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16856https://github.com/tbeu/matio/commit/651a8e28099edb5fbb9e4e1d4d3238848f446c9ahttps://lists.debian.org/debian-lts-announce/2020/06/msg00037.html
2019-10-13
Published