VDB
CVE-2019-20326
CVE-2019-20326
PUBLISHED
CVSS 7.800000190734863 HIGH
A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers to cause a crash and potentially execute arbitrary code via a crafted JPEG file.
EPSS 2.15% · 80.8th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
2.15%
80.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:18.04:LTS | gthumb | 0, 3:3.5.3-1, 3:3.5.4-1 |
| Ubuntu:20.04:LTS | gthumb | 0, 3:3.8.0-2.1, 3:3.8.0-2.1build1 |
| Ubuntu:Pro:16.04:LTS | gthumb | 3:3.3.1.is.3.2.8-0ubuntu3, 3:3.4.1-2, 3:3.4.1-4 |
Timeline
- Mar 16, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 29, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Jul 4, 2022 EPSS Score
- Sep 6, 2022 EPSS Score
- Jan 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 14, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-20326 third-party-advisory
- https://gitlab.gnome.org/GNOME/gthumb/commit/14860321ce3235d420498c4f81f21003d1fb78f4 third-party-advisory
- https://gitlab.gnome.org/GNOME/gthumb/commit/4faa5ce2358812d23a1147953ee76f59631590ad third-party-advisory
- https://ubuntu.com/security/notices/USN-5680-1 vendor-advisory
- https://ubuntu.com/security/notices/USN-5681-1 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-20326 third-party-advisory