Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-42144

Опубликовано: 04 мая 2026
Источник: debian

Описание

CImg Library is a C++ library for image processing. Prior to commit 4ca26bc, there is an integer overflow vulnerability in the W*H*D size computation inside _load_pnm() that can bypass the memory allocation guard. A crafted PNM/PGM/PPM file with large dimension values causes the overflow to wrap around, allocating an undersized buffer and potentially triggering a heap buffer overflow. Any application using CImg to load untrusted image files is affected. This issue has been patched via commit 4ca26bc.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cimgfixed3.5.2+dfsg-2package
cimgfixed3.5.2+dfsg-1+deb13u1trixiepackage
cimgno-dsabookwormpackage
cimgno-dsabullseyepackage

Примечания

  • https://github.com/GreycLab/CImg/security/advisories/GHSA-4663-63fm-44gc

  • https://github.com/GreycLab/CImg/issues/478

  • Fixed by: https://github.com/GreycLab/CImg/commit/4ca26bce4d8c61fcd1507d5f9401b9fb1222c27d (v3.7.5)

Связанные уязвимости

CVSS3: 6.1
ubuntu
3 месяца назад

CImg Library is a C++ library for image processing. Prior to commit 4ca26bc, there is an integer overflow vulnerability in the W*H*D size computation inside _load_pnm() that can bypass the memory allocation guard. A crafted PNM/PGM/PPM file with large dimension values causes the overflow to wrap around, allocating an undersized buffer and potentially triggering a heap buffer overflow. Any application using CImg to load untrusted image files is affected. This issue has been patched via commit 4ca26bc.

CVSS3: 6.1
nvd
3 месяца назад

CImg Library is a C++ library for image processing. Prior to commit 4ca26bc, there is an integer overflow vulnerability in the W*H*D size computation inside _load_pnm() that can bypass the memory allocation guard. A crafted PNM/PGM/PPM file with large dimension values causes the overflow to wrap around, allocating an undersized buffer and potentially triggering a heap buffer overflow. Any application using CImg to load untrusted image files is affected. This issue has been patched via commit 4ca26bc.