CVE-2019-19004: Autotrace Project Autotrace

Low severity, CVSS 3.3. EPSS: 1% chance of exploitation in the next 30 days.

A biWidth*biBitCnt integer overflow in input-bmp.c in autotrace 0.31.1 allows attackers to provide an unexpected input value to malloc via a malformed bitmap image.

Affected products

Published 2021-02-11. Last modified 2026-06-17.