Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-8710

Опубликовано: 26 янв. 2017
Источник: debian
EPSS Низкий

Описание

An exploitable heap write out of bounds vulnerability exists in the decoding of BPG images in Libbpg library. A crafted BPG image decoded by libbpg can cause an integer underflow vulnerability causing an out of bounds heap write leading to remote code execution. This vulnerability can be triggered via attempting to decode a crafted BPG image using Libbpg.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ffmpegnot-affectedpackage

Примечания

  • The libbpg library is not packaged in Debian but seem embedded in ffmpeg

  • http://blog.talosintel.com/2017/01/vulnerability-spotlight-libbpg-image.html

  • http://www.talosintelligence.com/reports/TALOS-2016-0223/

EPSS

Процентиль: 61%
0.00416
Низкий

Связанные уязвимости

CVSS3: 7.8
nvd
около 9 лет назад

An exploitable heap write out of bounds vulnerability exists in the decoding of BPG images in Libbpg library. A crafted BPG image decoded by libbpg can cause an integer underflow vulnerability causing an out of bounds heap write leading to remote code execution. This vulnerability can be triggered via attempting to decode a crafted BPG image using Libbpg.

CVSS3: 7.8
github
больше 3 лет назад

An exploitable heap write out of bounds vulnerability exists in the decoding of BPG images in Libbpg library. A crafted BPG image decoded by libbpg can cause an integer underflow vulnerability causing an out of bounds heap write leading to remote code execution. This vulnerability can be triggered via attempting to decode a crafted BPG image using Libbpg.

EPSS

Процентиль: 61%
0.00416
Низкий