A biWidth*biBitCnt integer overflow in input-bmp.c in autotrace 0.31.1 allows attackers to provide an unexpected input value to malloc via a malformed bitmap image.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-19004.json"