Published:2019/09/12  Last Updated:2019/10/17

JVN#39383894
apng-drawable vulnerable to integer overflow

Overview

apng-drawable (Animated Portable Network Graphics (APNG) image decoder for Android) contains an integer overflow vulnerability.

Products Affected

  • apng-drawable 1.0.0 to 1.6.0

Description

apng-drawable provided by LINE Corporation contains an integer overflow vulnerability (CWE-190).

Impact

An attacker may cause a denial of service (DoS) condition or execute arbitrary code.

Solution

Update the Software
The developer released apng-drawable that contains a fix for this vulnerability.
Update the software to the below version according to the information provided by the developer.

  • apng-drawable 1.7.0

Vendor Status

Vendor Status Last Update Vendor Notes
LINE Corporation Vulnerable 2019/10/16

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

CVSS v3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Base Score: 5.3
Attack Vector(AV) Physical (P) Local (L) Adjacent (A) Network (N)
Attack Complexity(AC) High (H) Low (L)
Privileges Required(PR) High (H) Low (L) None (N)
User Interaction(UI) Required (R) None (N)
Scope(S) Unchanged (U) Changed (C)
Confidentiality Impact(C) None (N) Low (L) High (H)
Integrity Impact(I) None (N) Low (L) High (H)
Availability Impact(A) None (N) Low (L) High (H)
CVSS v2 AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score: 6.8
Access Vector(AV) Local (L) Adjacent Network (A) Network (N)
Access Complexity(AC) High (H) Medium (M) Low (L)
Authentication(Au) Multiple (M) Single (S) None (N)
Confidentiality Impact(C) None (N) Partial (P) Complete (C)
Integrity Impact(I) None (N) Partial (P) Complete (C)
Availability Impact(A) None (N) Partial (P) Complete (C)

Credit

LINE Corporation reported this vulnerability to JPCERT/CC to notify users of its solution through JVN. JPCERT/CC and LINE Corporation coordinated under the Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2019-6007
JVN iPedia JVNDB-2019-000059

Update History

2019/10/17
LINE Corporation update status