CVE-2019-13504 is an out-of-bounds read vulnerability (CWE-125) in Exiv2 versions through 0.27.2, specifically within the Exiv2::MrwImage::readMetadata function. This flaw affects products utilizing Exiv2, including Debian Linux distributions. Rated 6.5 MEDIUM on CVSS, it requires user interaction (UI:R) and can lead to a high availability impact (A:H) if exploited. There is no evidence of active exploitation, and no public exploit code exists in Metasploit or ExploitDB, with minimal community discussion and no media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.27.2CPE matchmatch criteria | cpe:2.3:a:exiv2:exiv2:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2019-13504
Jan 11, 2022exiv2: out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp
Jul 10, 2019There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp in Exiv2 through 0.27.2.
Jul 9, 2019