LiveActive security incident?Get immediate response
CVE Record

CVE-2019-1010189: mgetty prior to version 1.2.1 is affected by: Infinite Loop.

mgetty prior to version 1.2.1 is affected by: Infinite Loop. The impact is: DoS, the program does never terminates. The component is: g3/g32pbm.c. The attack vector is: Local, the user should open a specially crafted file. The fixed version is: 1.2.1.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysislow

Security readout for executives and security teams

Plain-English summary

CVE-2019-1010189 is a denial-of-service flaw in mgetty before 1.2.1. A local user would need to open a specially crafted file, causing the affected program to enter an infinite loop and not terminate. This is mainly an availability risk for systems that still use mgetty or process G3 fax files.

Executive priority

Treat this as a low-priority availability issue unless mgetty is used in automated file processing or on shared legacy hosts. Prioritize routine patching and exposure confirmation rather than emergency response.

Technical view

The CVE identifies an infinite loop in mgetty's g3/g32pbm.c component before version 1.2.1. The stated impact is denial of service because the program never terminates. The attack vector is local file handling. The source bundle does not provide CVSS, CWE, or detailed root-cause mechanics.

Likely exposure

Exposure is most likely on legacy Linux or Unix systems with mgetty installed, especially where G3 fax conversion utilities process local or user-supplied files. Systems without mgetty, or already on 1.2.1 or a fixed distribution package, are not indicated as affected.

Exploitation context

The source bundle reports no KEV listing and provides no evidence of active exploitation. Exploitation requires local interaction with a specially crafted file, not remote network access. Risk increases if automated workflows process untrusted fax image files.

Researcher notes

Evidence is limited to the CVE description, X41 reference, and Fedora advisory. The fixed version is named as 1.2.1, but no CVSS vector or CWE is provided in the bundle. Do not assume remote exploitability or active exploitation from these sources.

Mitigation direction

  • Upgrade mgetty to version 1.2.1 or a distribution package containing the fix.
  • Apply relevant vendor or distribution advisories, including Fedora updates where applicable.
  • Restrict local access to mgetty conversion utilities on shared systems.
  • Avoid processing untrusted G3 fax files until systems are confirmed fixed.
  • Monitor vendor guidance if using downstream-packaged mgetty versions.

Validation and detection

  • Inventory systems for installed mgetty packages and versions.
  • Confirm affected hosts are at mgetty 1.2.1 or a fixed vendor build.
  • Check whether g3/g32pbm utilities process user-supplied or automated file inputs.
  • Review batch jobs or services that invoke mgetty fax conversion components.
  • Record systems without mgetty as not applicable for this CVE.
Prepared
Confidence
high
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2019-1010189 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
mgettymgettyprior to version 1.2.1 [fixed: 1.2.1]Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.