CVE-2019-6976

libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c does not zero out allocated memory. This can result in leaking raw process memory contents through the output image.
Configurations

Configuration 1 (hide)

cpe:2.3:a:libvips:libvips:*:*:*:*:*:*:*:*

History

29 Sep 2023, 11:18

Type Values Removed Values Added
CPE cpe:2.3:a:libvips_project:libvips:*:*:*:*:*:*:*:* cpe:2.3:a:libvips:libvips:*:*:*:*:*:*:*:*
First Time Libvips libvips
Libvips

Information

Published : 2019-01-26 23:29

Updated : 2023-12-10 12:44


NVD link : CVE-2019-6976

Mitre link : CVE-2019-6976

CVE.ORG link : CVE-2019-6976


JSON object : View

Products Affected

libvips

  • libvips
CWE
CWE-908

Use of Uninitialized Resource