CVE-2019-13109
Published: 30 June 2019
An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a chunkLength - iccOffset subtraction.
Priority
CVSS 3 base score: 6.5
Notes
Author | Note |
---|---|
leosilva | Same as CVE-2019-13108. Could not reproduce the poc and code affected is not present |