Описание
libvips is a fast image processing library with low memory needs. The vipsload operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. This has been patched in version 8.18.1.
A flaw was found in libvips, an image processing library. The vipsload operation, responsible for loading images, could incorrectly calculate image dimensions. This error leads to an integer overflow, which subsequently causes a heap-based buffer overflow. A local attacker with low privileges could exploit this vulnerability to execute arbitrary code or cause the application to crash, leading to a denial of service.
Отчет
Important: A heap-based buffer overflow flaw in libvips' vipsload operation allows a local attacker with low privileges to achieve arbitrary code execution or cause a denial of service. This vulnerability arises from incorrect image dimension calculations, leading to an integer overflow. The impact is significant due to the potential for code execution, even with limited access.
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7.3 High
CVSS3
Связанные уязвимости
libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. This has been patched in version 8.18.1.
libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. This has been patched in version 8.18.1.
libvips is a fast image processing library with low memory needs. The ...
EPSS
7.3 High
CVSS3