{"schema_version":"1.7.5","id":"CVE-2019-1010006","published":"2019-07-15T02:15:10.370Z","modified":"2026-07-08T05:54:42.737552893Z","related":["SUSE-SU-2019:14141-1","SUSE-SU-2019:2052-1","SUSE-SU-2019:2080-1","SUSE-SU-2019:2080-2","SUSE-SU-2019:2098-1","openSUSE-SU-2019:1908-1","openSUSE-SU-2024:10742-1"],"details":"Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The component is: backend/tiff/tiff-document.c. The attack vector is: Victim must open a crafted PDF file. The issue occurs because of an incorrect integer overflow protection mechanism in tiff_document_render and tiff_document_get_thumbnail.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gnome/evince","events":[{"introduced":"b53823ee76a10ac4c306d4254c7bce82d1ee9ecb"},{"last_affected":"b53823ee76a10ac4c306d4254c7bce82d1ee9ecb"}],"database_specific":{"cpe":"cpe:2.3:a:gnome:evince:3.26.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.26.0"},{"last_affected":"3.26.0"}],"source":"CPE_STRING"}}],"versions":["3.26.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-1010006.json"}}],"references":[{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00046.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/08/msg00013.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/08/msg00014.html"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2020/Feb/18"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4067-1/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2020/dsa-4624"},{"type":"REPORT","url":"http://bugzilla.maptools.org/show_bug.cgi?id=2745"},{"type":"REPORT","url":"https://bugzilla.gnome.org/show_bug.cgi?id=788980"}],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*"],"extracted_events":[{"introduced":"16.04"},{"last_affected":"16.04"}],"source":"CPE_STRING","vendor_product":"canonical:ubuntu_linux"},{"cpes":["cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0"},{"last_affected":"8.0"},{"introduced":"9.0"},{"last_affected":"9.0"},{"introduced":"10.0"},{"last_affected":"10.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux"},{"cpes":["cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*","cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"15.0"},{"last_affected":"15.0"},{"introduced":"15.1"},{"last_affected":"15.1"}],"source":"CPE_STRING","vendor_product":"opensuse:leap"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}