CVE-2019-19004
published 2021-02-11CVE-2019-19004: A biWidth*biBitCnt integer overflow in input-bmp.c in autotrace 0.31.1 allows attackers to provide an unexpected input value to malloc via a malformed bitmap…
PriorityP48low3.3CVSS 3.1
AVLACLPRNUIRSUCNINAL
EPSS
1.02%
59.5th percentile
A biWidth*biBitCnt integer overflow in input-bmp.c in autotrace 0.31.1 allows attackers to provide an unexpected input value to malloc via a malformed bitmap image.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| autotrace_project | autotrace | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rjwr-8pfc-m94f: A biWidth*biBitCnt integer overflow in input-bmp
ghsa_unreviewed·2022-05-24
CVE-2019-19004 [HIGH] CWE-190 GHSA-rjwr-8pfc-m94f: A biWidth*biBitCnt integer overflow in input-bmp
A biWidth*biBitCnt integer overflow in input-bmp.c in autotrace 0.31.1 allows attackers to provide an unexpected input value to malloc via a malformed bitmap image.
OSV
CVE-2019-19004: A biWidth*biBitCnt integer overflow in input-bmp
osv·2021-02-11·CVSS 3.3
CVE-2019-19004 [LOW] CVE-2019-19004: A biWidth*biBitCnt integer overflow in input-bmp
A biWidth*biBitCnt integer overflow in input-bmp.c in autotrace 0.31.1 allows attackers to provide an unexpected input value to malloc via a malformed bitmap image.
Red Hat
autotrace: integer overflow in input-bmp.c
vendor_redhat·2021-02-11·CVSS 3.3
CVE-2019-19004 [LOW] CWE-190 autotrace: integer overflow in input-bmp.c
autotrace: integer overflow in input-bmp.c
A biWidth*biBitCnt integer overflow in input-bmp.c in autotrace 0.31.1 allows attackers to provide an unexpected input value to malloc via a malformed bitmap image.
Package: autotrace (Red Hat Enterprise Linux 6) - Out of support scope
Package: autotrace (Red Hat Enterprise Linux 7) - Out of support scope
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/autotrace/autotrace/commits/masterhttps://github.com/autotrace/autotrace/commits/master/src/input-bmp.chttps://github.com/autotrace/autotrace/pull/40https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NC6MUH2RLVEA634LHBNZ2KO7MQKI2RDZ/https://github.com/autotrace/autotrace/commits/masterhttps://github.com/autotrace/autotrace/commits/master/src/input-bmp.chttps://github.com/autotrace/autotrace/pull/40https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NC6MUH2RLVEA634LHBNZ2KO7MQKI2RDZ/
2021-02-11
Published