Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-32323

Опубликовано: 14 июл. 2022
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

AutoTrace v0.40.0 was discovered to contain a heap overflow via the ReadImage function at input-bmp.c:660.

A buffer overflow flaw was found in the autotrace package. This flaw allows an attacker to trick the user into opening a maliciously crafted BMP image, triggering arbitrary code execution or causing the application to crash.

Отчет

The inkscape package distributed with Red Hat Enterprise Linux 9 is not affected by this issue. Although it ships autotrace as a bundled dependency, it does not include the affected BMP reader code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6autotraceOut of support scope
Red Hat Enterprise Linux 7autotraceOut of support scope
Red Hat Enterprise Linux 9inkscapeNot affected
Red Hat Enterprise Linux 9inkscape:flatpak/inkscapeNot affected
Red Hat Enterprise Linux 8autotraceFixedRHSA-2023:306716.05.2023
Red Hat Enterprise Linux 9autotraceFixedRHSA-2023:258909.05.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=2107471autotrace: heap-buffer overflow via the ReadImage() at input-bmp.c

EPSS

Процентиль: 21%
0.00067
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
около 3 лет назад

AutoTrace v0.40.0 was discovered to contain a heap overflow via the ReadImage function at input-bmp.c:660.

CVSS3: 7.3
nvd
около 3 лет назад

AutoTrace v0.40.0 was discovered to contain a heap overflow via the ReadImage function at input-bmp.c:660.

CVSS3: 7.3
debian
около 3 лет назад

AutoTrace v0.40.0 was discovered to contain a heap overflow via the Re ...

suse-cvrf
почти 3 года назад

Security update for autotrace

suse-cvrf
почти 3 года назад

Security update for autotrace

EPSS

Процентиль: 21%
0.00067
Низкий

7.3 High

CVSS3