Vulnerability Details CVE-2019-1010174
CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_network() function. The attack vector is: Loading an image from a user-controllable url can lead to command injection, because no string sanitization is done on the url. The fixed version is: v.2.3.4.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.131
EPSS Ranking 93.8%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2019-1010174
-
cpe:2.3:a:cimg:cimg_library:-
-
cpe:2.3:a:cimg:cimg_library:2.3.0
-
cpe:2.3:a:cimg:cimg_library:2.3.1
-
cpe:2.3:a:cimg:cimg_library:2.3.2
-
cpe:2.3:a:cimg:cimg_library:2.3.3
-
cpe:2.3:o:debian:debian_linux:8.0
-
cpe:2.3:o:debian:debian_linux:9.0