CVE-2019-17263 describes a heap-based buffer over-read vulnerability in libyal libfwsi versions prior to 20191006, specifically within the libfwsi_extension_block_copy_from_byte_stream function. This low-severity vulnerability (CVSS 3.3) could lead to a denial of service, affecting the libfwsi_project and libfwsi products. The attack requires local access and has low complexity, with no impact on confidentiality or integrity. There is no evidence of active exploitation, public exploit code, or significant community discussion, and the vendor has disputed the vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20191006CPE matchmatch criteria | cpe:2.3:a:libfwsi_project:libfwsi:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.