{"id":"CVE-2020-19497","details":"Integer overflow vulnerability in Mat_VarReadNextInfo5 in mat5.c in tbeu matio (aka MAT File I/O Library) 1.5.17, allows attackers to cause a Denial of Service or possibly other unspecified impacts.","modified":"2026-07-08T20:30:50.092248Z","published":"2021-07-21T18:15:09.097Z","references":[{"type":"FIX","url":"https://github.com/tbeu/matio/commit/5fa49ef9fc4368fe3d19b5fdaa36d8fa5e7f4606"},{"type":"FIX","url":"https://github.com/tbeu/matio/issues/121"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tbeu/matio","events":[{"introduced":"64f793668e09216029447990702c145403d14375"},{"last_affected":"64f793668e09216029447990702c145403d14375"},{"fixed":"5fa49ef9fc4368fe3d19b5fdaa36d8fa5e7f4606"}],"database_specific":{"source":["CPE_STRING","REFERENCES"],"cpe":"cpe:2.3:a:matio_project:matio:1.5.17:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.5.17"},{"last_affected":"1.5.17"}]}}],"versions":["1.5.17","v1.5.17"],"database_specific":{"vanir_signatures":[{"digest":{"function_hash":"168464128060177551819576737395990941673","length":7714},"id":"CVE-2020-19497-50629e9c","signature_type":"Function","signature_version":"v1","source":"https://github.com/tbeu/matio/commit/5fa49ef9fc4368fe3d19b5fdaa36d8fa5e7f4606","target":{"file":"src/mat5.c","function":"ReadNextCell"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"46882531944099989651222743139195519614","length":6709},"id":"CVE-2020-19497-6f7c70f5","signature_type":"Function","signature_version":"v1","source":"https://github.com/tbeu/matio/commit/5fa49ef9fc4368fe3d19b5fdaa36d8fa5e7f4606","target":{"function":"Mat_VarReadNextInfo5","file":"src/mat5.c"}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/tbeu/matio/commit/5fa49ef9fc4368fe3d19b5fdaa36d8fa5e7f4606","target":{"file":"src/mat5.c"},"deprecated":false,"digest":{"line_hashes":["125997178291972357618424918322236905924","321298351454805353948894525003263998383","184340553889561575940288178441419672789","106894594511672106424774003214651813625","207476051808605968427141550520185821547","131582593453526897823171401671890009069","2145031563628040017002085798389648280","320299113391535142622938725597417605848","257712420465320408768335256384395746800","80759247968947579170936256013164501781","88668150995638720969129518123545621303","237169908827737954555765976147573584135","16497057057782366858346689961421958631","71348519064663219030906290790911215836","136506596555331688855412147482706340004","85781026977752442034393402922790771397","94696010855407425396805131175942085213","277969012940951584292668734314784759444","324758881292432488724986214737008527587","16520299461650942293346512680769282912","85781026977752442034393402922790771397","94696010855407425396805131175942085213","277969012940951584292668734314784759444","92525313498758893867887233041218288034"],"threshold":0.9},"id":"CVE-2020-19497-84f975f7"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-19497.json","vanir_signatures_modified":"2026-07-08T20:30:50Z"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}