SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-11459

The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF…

MEDIUM 5.5EPSS 1.44%

Does this matter?

Lower severity and a low EPSS score (1.44%). Track it; it rarely justifies an emergency change on its own.

Description

The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS
1.44% probability · 72th percentile
CISA KEV
Not listed
Weakness
CWE-754, CWE-908
Affected
gnome/evince · canonical/ubuntu linux · fedoraproject/fedora · debian/debian linux · redhat/enterprise linux · redhat/enterprise linux eus · redhat/enterprise linux server aus · redhat/enterprise linux server tus · opensuse/leap
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.