Medium severity5.5OSV Advisory· Published Apr 22, 2019· Updated Jun 17, 2026
CVE-2019-11459
CVE-2019-11459
Description
The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
62- osv-coords37 versionspkg:rpm/almalinux/gdk-pixbuf2pkg:rpm/almalinux/gdk-pixbuf2-develpkg:rpm/almalinux/gdk-pixbuf2-modulespkg:rpm/almalinux/gdk-pixbuf2-xlibpkg:rpm/almalinux/gdk-pixbuf2-xlib-develpkg:rpm/almalinux/gnome-desktop3pkg:rpm/almalinux/gnome-desktop3-develpkg:rpm/almalinux/pidginpkg:rpm/almalinux/pidgin-develpkg:rpm/suse/evince&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/evince&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/evince&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/evince&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/evince&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/evince&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4pkg:rpm/suse/evince&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/evince&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/evince&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/evince&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/evince&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/evince&distro=SUSE%20Enterprise%20Storage%205pkg:rpm/suse/evince&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/evince&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/evince&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/evince&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015pkg:rpm/suse/evince&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/evince&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/opensuse/evince&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/evince&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/evince&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP1pkg:rpm/almalinux/libpurplepkg:rpm/almalinux/libpurple-develpkg:rpm/suse/evince&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/evince&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP4pkg:rpm/suse/evince&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/opensuse/evince&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/evince&distro=openSUSE%20Tumbleweed
< 2.36.12-5.el8+ 36 more
- (no CPE)range: < 2.36.12-5.el8
- (no CPE)range: < 2.36.12-5.el8
- (no CPE)range: < 2.36.12-5.el8
- (no CPE)range: < 2.36.12-5.el8
- (no CPE)range: < 2.36.12-5.el8
- (no CPE)range: < 3.32.2-1.el8
- (no CPE)range: < 3.32.2-1.el8
- (no CPE)range: < 2.13.0-5.el8
- (no CPE)range: < 2.13.0-5.el8
- (no CPE)range: < 3.20.2-6.27.1
- (no CPE)range: < 3.20.2-6.27.1
- (no CPE)range: < 3.20.2-6.27.1
- (no CPE)range: < 3.20.2-6.27.1
- (no CPE)range: < 3.20.2-6.27.1
- (no CPE)range: < 3.20.2-6.27.1
- (no CPE)range: < 3.20.2-6.27.1
- (no CPE)range: < 3.20.2-6.27.1
- (no CPE)range: < 3.20.2-6.27.1
- (no CPE)range: < 3.20.2-6.27.1
- (no CPE)range: < 3.20.2-6.27.1
- (no CPE)range: < 3.20.2-6.27.1
- (no CPE)range: < 3.20.2-6.27.1
- (no CPE)range: < 3.10.3-2.8.1
- (no CPE)range: < 2.28.2-0.7.8.1
- (no CPE)range: < 3.26.0+20180128.1bd86963-4.7.3
- (no CPE)range: < 3.20.2-6.27.1
- (no CPE)range: < 3.20.2-6.27.1
- (no CPE)range: < 3.26.0+20180128.1bd86963-lp151.4.3.1
- (no CPE)range: < 2.28.2-0.7.8.1
- (no CPE)range: < 3.26.0+20180128.1bd86963-4.7.3
- (no CPE)range: < 2.13.0-5.el8
- (no CPE)range: < 2.13.0-5.el8
- (no CPE)range: < 3.20.2-6.27.1
- (no CPE)range: < 3.20.2-6.27.1
- (no CPE)range: < 3.10.3-2.8.1
- (no CPE)range: < 3.26.0+20180128.1bd86963-lp151.4.3.1
- (no CPE)range: < 40.4-1.3
cpe:2.3:a:gnome:evince:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:gnome:evince:*:*:*:*:*:*:*:*range: <=3.32.0
- (no CPE)range: <=3.32.0
- (no CPE)range: 3.1.2, 3.1.90, 3.1.90.1, …
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*+ 3 more
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_aus:8.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_tus:8.6:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
10- gitlab.gnome.org/GNOME/evince/issues/1129nvdPatchThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-06/msg00089.htmlnvdMailing ListThird Party Advisory
- access.redhat.com/errata/RHSA-2019:3553nvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2019/08/msg00013.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2019/08/msg00014.htmlnvdMailing ListThird Party Advisory
- seclists.org/bugtraq/2020/Feb/18nvdMailing ListThird Party Advisory
- usn.ubuntu.com/3959-1/nvdThird Party Advisory
- www.debian.org/security/2020/dsa-4624nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7LU4YZK5S46TZAH4J3NYYUYFMOC47LJG/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YJ6R7NMY44IHIQIY24CV3WV2GLGJPQPZ/nvd
News mentions
0No linked articles in our index yet.