Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-7263

Опубликовано: 26 мар. 2017
Источник: debian
EPSS Низкий

Описание

The bm_readbody_bmp function in bitmap_io.c in Potrace 1.14 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted BMP image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8698.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
potracefixed1.15-1package
potraceno-dsastretchpackage
potraceno-dsajessiepackage
potraceno-dsawheezypackage

Примечания

  • https://blogs.gentoo.org/ago/2017/03/03/potrace-heap-based-buffer-overflow-in-bm_readbody_bmp-bitmap_io-c-incomplete-fix-for-cve-2016-8698/

  • Proposed patch: https://github.com/asarubbo/poc/blob/master/00219-potrace-heapoverflow-bm_readbody_bmp-PATCH

  • This CVE is for an incomplete fix of CVE-2016-8698

EPSS

Процентиль: 57%
0.0035
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 9 лет назад

The bm_readbody_bmp function in bitmap_io.c in Potrace 1.14 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted BMP image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8698.

CVSS3: 7.8
nvd
почти 9 лет назад

The bm_readbody_bmp function in bitmap_io.c in Potrace 1.14 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted BMP image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8698.

CVSS3: 7.8
github
больше 3 лет назад

The bm_readbody_bmp function in bitmap_io.c in Potrace 1.14 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted BMP image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8698.

EPSS

Процентиль: 57%
0.0035
Низкий