Описание
In ffjpeg (commit hash: caade60), the function bmp_load() in bmp.c contains an integer overflow vulnerability, which eventually results in the heap overflow in jfif_encode() in jfif.c. This is due to the incomplete patch for issue 38
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:rockcarry:ffjpeg:2021-12-06:*:*:*:*:*:*:*
EPSS
Процентиль: 53%
0.00302
Низкий
6.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-190
Связанные уязвимости
CVSS3: 6.5
github
почти 4 года назад
In ffjpeg (commit hash: caade60), the function bmp_load() in bmp.c contains an integer overflow vulnerability, which eventually results in the heap overflow in jfif_encode() in jfif.c. This is due to the incomplete patch for issue 38
EPSS
Процентиль: 53%
0.00302
Низкий
6.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-190