---
title: "CVE-2019-5087\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2019-5087?format=md
keywords: index, follow
---

# CVE-2019-5087

Publication date 21 November 2019

Last updated 25 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**8.8 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2019-5087?format=md#impact-score)

Toggle side navigation

## Description

An exploitable integer overflow vulnerability exists in the
flattenIncrementally function in the xcf2png and xcf2pnm binaries of
xcftools 1.0.7. An integer overflow can occur while calculating the row's
allocation size, that could be exploited to corrupt memory and eventually
execute arbitrary code. In order to trigger this vulnerability, a victim
would need to open a specially crafted XCF file.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| xcftools | 23.04 lunar | Not in release |
| 22.10 kinetic | Not in release |
| 22.04 LTS jammy | Not in release |
| 21.10 impish | Not in release |
| 21.04 hirsute | Not in release |
| 20.10 groovy | Ignored end of life |
| 20.04 LTS focal | Fixed 1.0.7-6ubuntu0.20.04.1 |
| 19.10 eoan | Ignored end of life |
| 19.04 disco | Ignored end of life |
| 18.04 LTS bionic | Fixed 1.0.7-6ubuntu0.1 |
| 16.04 LTS xenial | Fixed 1.0.7-5ubuntu0.1~esm1  Ubuntu Pro |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

### Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

[Get Ubuntu Pro](https://ubuntu.com/pro)
[30-day free trial](https://ubuntu.com/pro/free-trial)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

8.8 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | Required |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 8.8 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5087)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-5087)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2019-5087)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2019-5087)

### Related Ubuntu Security Notices (USN)

+ [USN-5988-1](https://usn.ubuntu.com/USN-5988-1)
+ Xcftools vulnerabilities
+ 29 March 2023

### Other references

* <https://talosintelligence.com/vulnerability_reports/TALOS-2019-0879>
* <https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0879>
* <https://www.cve.org/CVERecord?id=CVE-2019-5087>
