VYPR
Critical severity9.8NVD Advisory· Published Jul 25, 2019· Updated Jun 17, 2026

CVE-2019-1010174

CVE-2019-1010174

Description

CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_network() function. The attack vector is: Loading an image from a user-controllable url can lead to command injection, because no string sanitization is done on the url. The fixed version is: v.2.3.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • CImg/Cimg Library3 versions
    cpe:2.3:a:cimg:cimg_library:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:cimg:cimg_library:*:*:*:*:*:*:*:*range: <2.3.4
    • (no CPE)range: v.2.3.3 and earlier [fixed: v.2.3.4]
    • (no CPE)range: <=2.3.3
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.