Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2019-12214

Published: 20 May 2019

In FreeImage 3.18.0, an out-of-bounds access occurs because of mishandling of the OpenJPEG j2k_read_ppm_v3 function in j2k.c. The value of l_N_ppm comes from the file read in, and the code does not consider that l_N_ppm may be greater than the size of p_header_data.

Notes

AuthorNote
ebarretto
No fix available as of 2019-09-06.

Priority

Medium

Cvss 3 Severity Score

7.5

Score breakdown

Status

Package Release Status
freeimage
Launchpad, Ubuntu, Debian
bionic Deferred
(2019-09-06)
cosmic Ignored
(end of life)
disco Ignored
(end of life)
eoan Ignored
(end of life)
focal Deferred
(2019-09-06)
groovy Ignored
(end of life)
hirsute Ignored
(end of life)
impish Ignored
(end of life)
jammy Deferred
(2019-09-06)
kinetic Ignored
(end of life, was deferred [2019-09-06])
lunar Ignored
(end of life, was deferred [2019-09-06])
mantic Deferred
(2019-09-06)
trusty Deferred
(2019-09-06)
upstream Needs triage

xenial Deferred
(2019-09-06)

Severity score breakdown

Parameter Value
Base score 7.5
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact High
Vector CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H