VDB
CVE-2019-20326
CVE-2019-20326
PUBLISHED
A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers to cause a crash and potentially execute arbitrary code via a crafted JPEG file.
EPSS 3.96% · 88.6th percentile
Risk Scores
EPSS Score
3.96%
88.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:18.04:LTS | gthumb | 0, 3:3.5.3-1, 3:3.5.4-1 |
| Ubuntu:20.04:LTS | gthumb | 0, 3:3.8.0-2.1, 3:3.8.0-2.1build1 |
| Ubuntu:Pro:16.04:LTS | gthumb | 3:3.3.1.is.3.2.8-0ubuntu3, 3:3.4.1-2, 3:3.4.1-4 |
Exploit Intelligence
- Heap buffer overflow in GNOME gThumb and Linux Mint Pix (github-poc)
- Heap buffer overflow in GNOME gThumb and Linux Mint Pix (github-poc)
- Heap buffer overflow in GNOME gThumb and Linux Mint Pix (github-poc)
- Heap buffer overflow in GNOME gThumb and Linux Mint Pix (github-poc)
- Heap buffer overflow in GNOME gThumb and Linux Mint Pix (github-poc)
- https://github.com/Fysac/CVE-2019-20326 (nist-nvd)
- https://gitlab.gnome.org/GNOME/gthumb/commit/4faa5ce2358812d23a1147953ee76f59631590ad (circl)
- https://gitlab.gnome.org/GNOME/gthumb/commit/ca8f528209ab78935c30e42fe53bdf1a24f3cb44 (circl)
- https://gitlab.gnome.org/GNOME/gthumb/commits/master/extensions/cairo_io/cairo-image-surface-jpeg.c (circl)
- GLSA-202008-05 (circl)
…and 1 more exploits
Timeline
- Mar 16, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 29, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 11, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-20326 third-party-advisory
- https://gitlab.gnome.org/GNOME/gthumb/commit/14860321ce3235d420498c4f81f21003d1fb78f4 third-party-advisory
- https://gitlab.gnome.org/GNOME/gthumb/commit/4faa5ce2358812d23a1147953ee76f59631590ad third-party-advisory
- https://ubuntu.com/security/notices/USN-5680-1 vendor-advisory
- https://ubuntu.com/security/notices/USN-5681-1 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-20326 third-party-advisory