Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h34m-m7hc-cp2h

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small. (There is also a heap-based buffer over-read.)

In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small. (There is also a heap-based buffer over-read.)

EPSS

Процентиль: 63%
0.00452
Низкий

7.8 High

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 7 лет назад

In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small. (There is also a heap-based buffer over-read.)

CVSS3: 5.3
redhat
почти 7 лет назад

In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small. (There is also a heap-based buffer over-read.)

CVSS3: 7.8
nvd
почти 7 лет назад

In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small. (There is also a heap-based buffer over-read.)

CVSS3: 7.8
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 7.8
debian
почти 7 лет назад

In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer ...

EPSS

Процентиль: 63%
0.00452
Низкий

7.8 High

CVSS3

Дефекты

CWE-125