CVE-2019-2101
published 2019-06-07CVE-2019-2101: In uvc_parse_standard_control of uvc_driver.c, there is a possible out-of-bound read due to improper input validation. This could lead to local information…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.40%
32.8th percentile
In uvc_parse_standard_control of uvc_driver.c, there is a possible out-of-bound read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-111760968.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | android | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.19.37-1 (bookworm) | linux 4.19.37-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | >= 0 < 4.19.37-1 | 4.19.37-1 |
| linux | linux_kernel | >= 0 < 4.19.37-1 | 4.19.37-1 |
| linux | linux_kernel | >= 0 < 4.19.37-1 | 4.19.37-1 |
| linux | linux_kernel | >= 0 < 4.19.37-1 | 4.19.37-1 |
| linux | linux_kernel | >= 0 < 4.15.0-58.64 | 4.15.0-58.64 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (AWS) vulnerabilities
vendor_ubuntu·2019-09-02·CVSS 3.3
CVE-2018-13053 [LOW] Linux kernel (AWS) vulnerabilities
Title: Linux kernel (AWS) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the alarmtimer implementation in the Linux kernel
contained an integer overflow vulnerability. A local attacker could use
this to cause a denial of service. (CVE-2018-13053)
Wen Xu discovered that the XFS filesystem implementation in the Linux
kernel did not properly track inode validations. An attacker could use this
to construct a malicious XFS image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13093)
Wen Xu discovered that the f2fs file system implementation in the Linux
kernel did not properly validate metadata. An attacker could use this to
construct a malicious f2fs image that, when mounted, could cause a denial
of serv
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-08-13·CVSS 3.3
CVE-2018-13053 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the alarmtimer implementation in the Linux kernel
contained an integer overflow vulnerability. A local attacker could use
this to cause a denial of service. (CVE-2018-13053)
Wen Xu discovered that the XFS filesystem implementation in the Linux
kernel did not properly track inode validations. An attacker could use this
to construct a malicious XFS image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13093)
Wen Xu discovered that the f2fs file system implementation in the
Linux kernel did not properly validate metadata. An attacker could
use this to construct a malicious f2fs image that, when mounted,
could cause a denial of service (s
Android
CVE-2019-2101: UVC driver
vendor_android·2019-06-01·CVSS 5.5
CVE-2019-2101 [MEDIUM] CVE-2019-2101: UVC driver
Android Security Bulletin 2019-06-01
CVE: CVE-2019-2101
Severity: HIGH
Type: ID
Component: UVC driver
References: A-111760968*
Debian
CVE-2019-2101: linux - In uvc_parse_standard_control of uvc_driver.c, there is a possible out-of-bound ...
vendor_debian·2019·CVSS 5.5
CVE-2019-2101 [MEDIUM] CVE-2019-2101: linux - In uvc_parse_standard_control of uvc_driver.c, there is a possible out-of-bound ...
In uvc_parse_standard_control of uvc_driver.c, there is a possible out-of-bound read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-111760968.
Scope: local
bookworm: resolved (fixed in 4.19.37-1)
bullseye: resolved (fixed in 4.19.37-1)
forky: resolved (fixed in 4.19.37-1)
sid: resolved (fixed in 4.19.37-1)
trixie: resolved (fixed in 4.19.37-1)
GHSA
GHSA-574f-mhc6-4fgh: In uvc_parse_standard_control of uvc_driver
ghsa_unreviewed·2022-05-24
CVE-2019-2101 [MEDIUM] CWE-125 GHSA-574f-mhc6-4fgh: In uvc_parse_standard_control of uvc_driver
In uvc_parse_standard_control of uvc_driver.c, there is a possible out-of-bound read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-111760968.
OSV
linux-aws vulnerabilities
osv·2019-09-02·CVSS 3.3
CVE-2018-13053 [LOW] linux-aws vulnerabilities
linux-aws vulnerabilities
It was discovered that the alarmtimer implementation in the Linux kernel
contained an integer overflow vulnerability. A local attacker could use
this to cause a denial of service. (CVE-2018-13053)
Wen Xu discovered that the XFS filesystem implementation in the Linux
kernel did not properly track inode validations. An attacker could use this
to construct a malicious XFS image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13093)
Wen Xu discovered that the f2fs file system implementation in the Linux
kernel did not properly validate metadata. An attacker could use this to
construct a malicious f2fs image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13096, CVE-2018-13097, CVE-2018-13098,
CVE-2018-1309
OSV
linux, linux-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
osv·2019-08-13·CVSS 3.3
CVE-2018-13053 [LOW] linux, linux-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that the alarmtimer implementation in the Linux kernel
contained an integer overflow vulnerability. A local attacker could use
this to cause a denial of service. (CVE-2018-13053)
Wen Xu discovered that the XFS filesystem implementation in the Linux
kernel did not properly track inode validations. An attacker could use this
to construct a malicious XFS image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13093)
Wen Xu discovered that the f2fs file system implementation in the
Linux kernel did not properly validate metadata. An attacker could
use this to construct a malicious f2fs image that, when moun
OSV
CVE-2019-2101: In uvc_parse_standard_control of uvc_driver
osv·2019-06-07·CVSS 5.5
CVE-2019-2101 [MEDIUM] CVE-2019-2101: In uvc_parse_standard_control of uvc_driver
In uvc_parse_standard_control of uvc_driver.c, there is a possible out-of-bound read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-111760968.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-17282 exiv2: NULL pointer dereference in Exiv2::DataValue::copy in value.cpp leading to application crash
bugzilla·2018-09-24·CVSS 6.5
CVE-2018-17282 [MEDIUM] CVE-2018-17282 exiv2: NULL pointer dereference in Exiv2::DataValue::copy in value.cpp leading to application crash
CVE-2018-17282 exiv2: NULL pointer dereference in Exiv2::DataValue::copy in value.cpp leading to application crash
An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.
References:
https://github.com/Exiv2/exiv2/issues/457
Discussion:
Created exiv2 tracking bugs for this issue:
Affects: fedora-all [bug 1632491]
---
Statement:
This issue did not affect the versions of exiv2 as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7 prior to 7.5 as they did not include the vulnerable code.
---
Upstream patch:
https://github.com/Exiv2/exiv2/commit/670fb73dd5ee8acab90971c4878de29f9fc43a02
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2101 htt
Bugzilla
CVE-2018-14046 exiv2: heap-based buffer over-read in WebPImage::decodeChunks in webpimage.cpp
bugzilla·2018-07-16·CVSS 8.8
CVE-2018-14046 [HIGH] CVE-2018-14046 exiv2: heap-based buffer over-read in WebPImage::decodeChunks in webpimage.cpp
CVE-2018-14046 exiv2: heap-based buffer over-read in WebPImage::decodeChunks in webpimage.cpp
A flaw was found in Exiv2 0.26. A heap-based buffer over-read in WebPImage::decodeChunks in webpimage.cpp.
References:
https://github.com/Exiv2/exiv2/issues/378
Upstream patch:
https://github.com/Exiv2/exiv2/commit/505e2417e408abaf8f9fe9e5076f567a65cc59c3
Discussion:
Created exiv2 tracking bugs for this issue:
Affects: fedora-all [bug 1601629]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2101 https://access.redhat.com/errata/RHSA-2019:2101
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2018-14046
Bugzilla
CVE-2018-10772 exiv2: OOB read in pngimage.cpp:tEXtToDataBuf() allows for crash via crafted file
bugzilla·2018-06-25·CVSS 6.5
CVE-2018-10772 [MEDIUM] CVE-2018-10772 exiv2: OOB read in pngimage.cpp:tEXtToDataBuf() allows for crash via crafted file
CVE-2018-10772 exiv2: OOB read in pngimage.cpp:tEXtToDataBuf() allows for crash via crafted file
Exiv2 through version 0.26 is vulnerable to a segmentation fault in the pngimage.cpp:tEXtToDataBuf() function. An attacker could exploit this to cause a denial of service or via crafted file.
Product Bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1566260
Discussion:
Created exiv2 tracking bugs for this issue:
Affects: fedora-all [bug 1594628]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2101 https://access.redhat.com/errata/RHSA-2019:2101
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2018-10772
---
This issue has been a
Bugzilla
CVE-2018-12264 exiv2: integer overflow in getData function in preview.cpp
bugzilla·2018-06-13·CVSS 8.8
CVE-2018-12264 [HIGH] CVE-2018-12264 exiv2: integer overflow in getData function in preview.cpp
CVE-2018-12264 exiv2: integer overflow in getData function in preview.cpp
A flaw was found in Exiv2 0.26. An integer overflow in LoaderTiff::getData() in preview.cpp, leading to an out-of-bounds read in Exiv2::ValueType::setDataArea in value.hpp.
References:
https://github.com/Exiv2/exiv2/issues/366
https://github.com/TeamSeri0us/pocs/blob/master/exiv2/2-out-of-read-Poc
Patch:
https://github.com/Exiv2/exiv2/commit/341de4500ab993103c215bfb07d43d4a08654ac4
Discussion:
Created exiv2 tracking bugs for this issue:
Affects: fedora-all [bug 1590995]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2101 https://access.redhat.com/errata/RHSA-2019:2101
---
This bug is now closed. Further updates for individual products will be reflect
Bugzilla
CVE-2018-12265 exiv2: integer overflow in the LoaderExifJpeg class in preview.cpp
bugzilla·2018-06-13·CVSS 8.8
CVE-2018-12265 [HIGH] CVE-2018-12265 exiv2: integer overflow in the LoaderExifJpeg class in preview.cpp
CVE-2018-12265 exiv2: integer overflow in the LoaderExifJpeg class in preview.cpp
Exiv2 0.26 has an integer overflow in the LoaderExifJpeg class in preview.cpp, leading to an out-of-bounds read in Exiv2::MemIo::read in basicio.cpp.
References:
https://github.com/Exiv2/exiv2/issues/365
https://github.com/TeamSeri0us/pocs/blob/master/exiv2/1-out-of-read-Poc
Patch:
https://github.com/Exiv2/exiv2/commit/341de4500ab993103c215bfb07d43d4a08654ac4
Discussion:
Created exiv2 tracking bugs for this issue:
Affects: fedora-all [bug 1590998]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2101 https://access.redhat.com/errata/RHSA-2019:2101
---
This bug is now closed. Further updates for individual products will be reflected on the CVE p
Bugzilla
CVE-2018-11037 exiv2: information leak via a crafted file
bugzilla·2018-05-17·CVSS 6.5
CVE-2018-11037 [MEDIUM] CVE-2018-11037 exiv2: information leak via a crafted file
CVE-2018-11037 exiv2: information leak via a crafted file
A flaw was found in Exiv2 0.26, the Exiv2::PngImage::printStructure function in pngimage.cpp allows remote attackers to cause an information leak via a crafted file.
References:
https://github.com/Exiv2/exiv2/issues/307
Discussion:
Created exiv2 tracking bugs for this issue:
Affects: fedora-all [bug 1579486]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2101 https://access.redhat.com/errata/RHSA-2019:2101
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2018-11037
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-202
Bugzilla
CVE-2018-10998 exiv2: SIGABRT by triggering an incorrect Safe::add call
bugzilla·2018-05-17·CVSS 6.5
CVE-2018-10998 [MEDIUM] CVE-2018-10998 exiv2: SIGABRT by triggering an incorrect Safe::add call
CVE-2018-10998 exiv2: SIGABRT by triggering an incorrect Safe::add call
An issue was discovered in Exiv2 0.26. The readMetadata function in jp2image.cpp allows remote attackers to cause a denial of service (SIGABRT) by triggering an incorrect Safe::add call.
References:
https://github.com/Exiv2/exiv2/issues/303
Discussion:
Created exiv2 tracking bugs for this issue:
Affects: fedora-all [bug 1579486]
---
In RHEL 7, the PoC triggered a SIGABRT. Thus, this bug may have some deny of service effect (although not confirmed by upstream so far).
---
The SIGABRT happens just because the exiv2 app is not catching an intended throwed exception.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2101 https://access.redhat.com/errata/RHSA
Bugzilla
CVE-2018-10958 exiv2: SIGABRT caused by memory allocation in types.cpp:Exiv2::Internal::PngChunk::zlibUncompress()
bugzilla·2018-05-16·CVSS 6.5
CVE-2018-10958 [MEDIUM] CVE-2018-10958 exiv2: SIGABRT caused by memory allocation in types.cpp:Exiv2::Internal::PngChunk::zlibUncompress()
CVE-2018-10958 exiv2: SIGABRT caused by memory allocation in types.cpp:Exiv2::Internal::PngChunk::zlibUncompress()
In types.cpp in Exiv2 0.26, a large size value may lead to a SIGABRT during an attempt at memory allocation for an Exiv2::Internal::PngChunk::zlibUncompress call.
Upstream Issue:
https://github.com/Exiv2/exiv2/issues/302
Discussion:
Created exiv2 tracking bugs for this issue:
Affects: fedora-all [bug 1578661]
---
Upstream patch:
https://github.com/Exiv2/exiv2/pull/316/files
For RHEL 6 and 7 the code parts are in src/pngimage.cpp (not in src/pngchunk_int.cpp).
---
*** Bug 1579488 has been marked as a duplicate of this bug. ***
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2101 https://access.redhat.com/err
Bugzilla
CVE-2018-9305 exiv2: out of bounds read in IptcData::printStructure in iptc.c
bugzilla·2018-04-12·CVSS 8.1
CVE-2018-9305 [HIGH] CVE-2018-9305 exiv2: out of bounds read in IptcData::printStructure in iptc.c
CVE-2018-9305 exiv2: out of bounds read in IptcData::printStructure in iptc.c
In Exiv2 0.26, an out-of-bounds read in IptcData::printStructure in iptc.cpp
could result in a crash or information leak, due to use of the untrusted `len`
value without any check.
References:
https://github.com/Exiv2/exiv2/issues/263
https://github.com/xiaoqx/pocs/blob/master/exiv2/readme.md
Discussion:
Created exiv2 tracking bugs for this issue:
Affects: fedora-all [bug 1566727]
---
Statement:
This issue did not affect the versions of Exiv2 as shipped with Red Hat Enterprise Linux 6 and 7, up to 7.4, as they did not include support for printing IPTC Photo Metadata.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2101 https://access.redhat.com/er
Bugzilla
CVE-2018-8977 exiv2: invalid memory access in Exiv2::Internal::printCsLensFFFF function in canonmn_int.cpp
bugzilla·2018-03-27·CVSS 6.5
CVE-2018-8977 [MEDIUM] CVE-2018-8977 exiv2: invalid memory access in Exiv2::Internal::printCsLensFFFF function in canonmn_int.cpp
CVE-2018-8977 exiv2: invalid memory access in Exiv2::Internal::printCsLensFFFF function in canonmn_int.cpp
A flaw was found in Exiv2 0.26, the Exiv2::Internal::printCsLensFFFF function in canonmn_int.cpp allows remote attackers to cause a denial of service (invalid memory access) via a crafted file.
References:
https://github.com/Exiv2/exiv2/issues/247
Discussion:
Created exiv2 tracking bugs for this issue:
Affects: fedora-all [bug 1561214]
---
This issue does not affect the exiv2 version shipped in Red Hat Enterprise Linux 7.4. However, in Red Hat Enterprise Linux 7.5, exiv2 is rebased to the affected version (0.26).
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2101 https://access.redhat.com/errata/RHSA-2019:2101
---
T
Bugzilla
CVE-2018-8976 exiv2: out-of-bounds read in Exiv2::Internal::stringFormat image.cpp
bugzilla·2018-03-27·CVSS 6.5
CVE-2018-8976 [MEDIUM] CVE-2018-8976 exiv2: out-of-bounds read in Exiv2::Internal::stringFormat image.cpp
CVE-2018-8976 exiv2: out-of-bounds read in Exiv2::Internal::stringFormat image.cpp
A flaw was found in Exiv2 0.26, jpgimage.cpp allows remote attackers to cause a denial of service (image.cpp Exiv2::Internal::stringFormat out-of-bounds read) via a crafted file.
References:
https://github.com/Exiv2/exiv2/issues/246
Discussion:
Created exiv2 tracking bugs for this issue:
Affects: fedora-all [bug 1561214]
---
This issue does not affect the exiv2 version shipped in Red Hat Enterprise Linux 7.4. However, in Red Hat Enterprise Linux 7.5, exiv2 is rebased to the affected version (0.26).
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2101 https://access.redhat.com/errata/RHSA-2019:2101
---
This bug is now closed. Further updates
http://packetstormsecurity.com/files/154245/Kernel-Live-Patch-Security-Notice-LSN-0054-1.htmlhttps://lists.debian.org/debian-lts-announce/2019/07/msg00022.htmlhttps://source.android.com/security/bulletin/2019-06-01https://usn.ubuntu.com/4094-1/https://usn.ubuntu.com/4118-1/http://packetstormsecurity.com/files/154245/Kernel-Live-Patch-Security-Notice-LSN-0054-1.htmlhttps://lists.debian.org/debian-lts-announce/2019/07/msg00022.htmlhttps://source.android.com/security/bulletin/2019-06-01https://usn.ubuntu.com/4094-1/https://usn.ubuntu.com/4118-1/
2019-06-07
Published