Back to search
CVE-2019-1010174
Published: Jul 25, 2019
Modified: Aug 5, 2024
PUBLISHED
Description
CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_network() function. The attack vector is: Loading an image from a user-controllable url can lead to command injection, because no string sanitization is done on the url. The fixed version is: v.2.3.4.
| Vendor | Product | Versions |
|---|---|---|
CImg | The CImg Library | affected v.2.3.3 and earlier [fixed: v.2.3.4] |
References
[debian-lts-announce] 20190928 [SECURITY] [DLA 1934-1] cimg security update
mailing-list
x_refsource_MLIST
[debian-lts-announce] 20201030 [SECURITY] [DLA 2421-1] cimg security update
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now