vulnerability
Ubuntu: USN-6437-1 (CVE-2019-6976): VIPS vulnerabilities
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:L/Au:N/C:P/I:N/A:N) | Jan 26, 2019 | Oct 19, 2023 | Mar 27, 2026 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
Jan 26, 2019
Added
Oct 19, 2023
Modified
Mar 27, 2026
Description
libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c does not zero out allocated memory. This can result in leaking raw process memory contents through the output image.
Solutions
ubuntu-pro-upgrade-gir1-2-vips-8-0ubuntu-pro-upgrade-libvips-toolsubuntu-pro-upgrade-libvips42ubuntu-pro-upgrade-python-vipscc
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.