CVE-2019-6976

MEDIUM

libvips <8.7.4 - Memory Corruption

Title source: llm
STIX 2.1

Description

libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c does not zero out allocated memory. This can result in leaking raw process memory contents through the output image.

References (3)

Core 3
Core References
Third Party Advisory x_refsource_misc
https://github.com/libvips/libvips/releases/tag/v8.7.4
Technical Description, Third Party Advisory x_refsource_misc
https://blog.silentsignal.eu/2019/04/18/drop-by-drop-bleeding-through-libvips/

Scores

CVSS v3 5.3
EPSS 0.0027
EPSS Percentile 50.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-908
Status published
Products (1)
libvips/libvips < 8.7.4
Published Jan 26, 2019
Tracked Since Feb 18, 2026