Unrated severityOSV Advisory· Published Jan 26, 2019· Updated Aug 4, 2024
CVE-2019-6976
CVE-2019-6976
Description
libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c does not zero out allocated memory. This can result in leaking raw process memory contents through the output image.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
3- blog.silentsignal.eu/2019/04/18/drop-by-drop-bleeding-through-libvips/mitrex_refsource_MISC
- github.com/libvips/libvips/commit/00622428bda8d7521db8d74260b519fa41d69d0amitrex_refsource_MISC
- github.com/libvips/libvips/releases/tag/v8.7.4mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.