Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-42146

Опубликовано: 04 мая 2026
Источник: debian
EPSS Низкий

Описание

CImg Library is a C++ library for image processing. Prior to commit c3aacf5, the nb_colors field read from the BMP file header is used directly to compute an allocation size without validating it against the remaining file size. A crafted BMP file with a large nb_colors value triggers an out-of-memory condition, crashing any application that uses CImg to load untrusted BMP files. This issue has been patched via commit c3aacf5.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cimgfixed3.5.2+dfsg-2package
cimgfixed3.5.2+dfsg-1+deb13u1trixiepackage
cimgno-dsabookwormpackage
cimgno-dsabullseyepackage

Примечания

  • https://github.com/GreycLab/CImg/security/advisories/GHSA-g54r-qmgx-c6fv

  • https://github.com/GreycLab/CImg/issues/477

  • Fixed by: https://github.com/GreycLab/CImg/commit/c3aacf5b96ac1e54b7af1957c6737dbf3949f6d3 (v3.7.5)

EPSS

Процентиль: 2%
0.00119
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
3 месяца назад

CImg Library is a C++ library for image processing. Prior to commit c3aacf5, the nb_colors field read from the BMP file header is used directly to compute an allocation size without validating it against the remaining file size. A crafted BMP file with a large nb_colors value triggers an out-of-memory condition, crashing any application that uses CImg to load untrusted BMP files. This issue has been patched via commit c3aacf5.

CVSS3: 5.5
nvd
3 месяца назад

CImg Library is a C++ library for image processing. Prior to commit c3aacf5, the nb_colors field read from the BMP file header is used directly to compute an allocation size without validating it against the remaining file size. A crafted BMP file with a large nb_colors value triggers an out-of-memory condition, crashing any application that uses CImg to load untrusted BMP files. This issue has been patched via commit c3aacf5.

EPSS

Процентиль: 2%
0.00119
Низкий