ZeroHour

CVE-2019-11459

CVSS 3.1
5.5 medium
EPSS
1%p72
Published
()
Modified
Description

The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.

Vendors
gnomecanonicalfedoraprojectdebianredhatopensuse
Products
evince, ubuntu linux, fedora, debian linux, enterprise linux, enterprise linux eus, enterprise linux server aus, enterprise linux server tus, leap
Weakness
CWE-754, CWE-908
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.