CVE-2019-19004: Autotrace Project Autotrace
Low severity, CVSS 3.3. EPSS: 1% chance of exploitation in the next 30 days.
A biWidth*biBitCnt integer overflow in input-bmp.c in autotrace 0.31.1 allows attackers to provide an unexpected input value to malloc via a malformed bitmap image.
Affected products
- Autotrace Project Autotrace: version 0.31.1 only
- Fedoraproject Fedora: version 34 only
Published 2021-02-11. Last modified 2026-06-17.