CVE-2019-6976

libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c does not zero out allocated memory. This can result in leaking raw process memory contents through the output image.
Configurations

Configuration 1

cpe:2.3:a:libvips_project:libvips:*:*:*:*:*:*:*:*

Information

Published : 2019-01-26 11:29

Updated : 2020-08-24 05:37


NVD link : CVE-2019-6976

Mitre link : CVE-2019-6976

Products Affected
No products.
CWE