Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-8703

Опубликовано: 31 янв. 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8
CVSS3: 7.8

Описание

Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a different vulnerability than CVE-2016-8698, CVE-2016-8699, CVE-2016-8700, CVE-2016-8701, and CVE-2016-8702.

РелизСтатусПримечание
artful

not-affected

uses system potrace
bionic

not-affected

uses system potrace
cosmic

not-affected

uses system potrace
devel

not-affected

uses system potrace
disco

not-affected

uses system potrace
esm-apps/bionic

not-affected

uses system potrace
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [no attack vector]]
esm-infra/xenial

not-affected

no attack vector
precise

ignored

end of life
precise/esm

DNE

precise was deferred [2016-12-08]

Показывать по

РелизСтатусПримечание
artful

not-affected

1.14-2
bionic

not-affected

1.14-2
cosmic

not-affected

1.14-2
devel

not-affected

1.14-2
disco

not-affected

1.14-2
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needed]
esm-infra/bionic

not-affected

1.14-2
esm-infra/xenial

not-affected

1.13-2
precise

ignored

end of life
precise/esm

DNE

precise was deferred [2016-12-08]

Показывать по

EPSS

Процентиль: 68%
0.00559
Низкий

6.8 Medium

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
около 9 лет назад

Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a different vulnerability than CVE-2016-8698, CVE-2016-8699, CVE-2016-8700, CVE-2016-8701, and CVE-2016-8702.

CVSS3: 7.8
debian
около 9 лет назад

Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_i ...

CVSS3: 7.8
github
больше 3 лет назад

Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a different vulnerability than CVE-2016-8698, CVE-2016-8699, CVE-2016-8700, CVE-2016-8701, and CVE-2016-8702.

EPSS

Процентиль: 68%
0.00559
Низкий

6.8 Medium

CVSS2

7.8 High

CVSS3