PT-2019-11502 · Mgetty+2 · Mgetty+2

CVE-2019-1010190

·

Published

2019-07-24

·

Updated

2024-08-14

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: mgetty versions prior to 1.2.1
Description: The issue is related to an out-of-bounds read, which can cause a denial of service (DoS) and potentially crash the program if the memory is not mapped. This is due to the putwhitespan() function in g3/pbm2g3.c. The attack vector is local, requiring the victim to open a specially crafted file.
Recommendations: For versions prior to 1.2.1, update to version 1.2.1 to resolve the issue. As a temporary workaround, consider avoiding the use of the putwhitespan() function in g3/pbm2g3.c until the update is applied. Restrict access to specially crafted files to minimize the risk of exploitation.

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3522
ALT-PU-2020-3533
ALT-PU-2024-11129
CVE-2019-1010190
OPENSUSE-SU-2020:0506-1
OPENSUSE-SU-2020_0506-1
SUSE-SU-2020:0853-1
SUSE-SU-2020:0957-1
SUSE-SU-2020_0853-1
SUSE-SU-2020_0957-1

Affected Products

Alt Linux
Suse
Mgetty