cbcvebase.
CVE-2019-5086
published 2019-11-21

CVE-2019-5086: An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools, version 1.0.7. An…

PriorityP347high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
3.15%
86.6th percentile
An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools, version 1.0.7. An integer overflow can occur while walking through tiles that could be exploited to corrupt memory and execute arbitrary code. In order to trigger this vulnerability, a victim would need to open a specially crafted XCF file.

Affected

6 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
xcftools_projectxcftools
xcftools_projectxcftools
xcftools_projectxcftools>= 0 < 1.0.7-6ubuntu0.11.0.7-6ubuntu0.1
xcftools_projectxcftools>= 0 < 1.0.7-6ubuntu0.20.04.11.0.7-6ubuntu0.20.04.1
xcftools_projectxcftools>= 0 < 1.0.7-5ubuntu0.1~esm11.0.7-5ubuntu0.1~esm1

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.