PT-2016-6610 · Bellard+1 · Libbpg+1
Puzzor
·
Publicado
2016-07-15
·
Atualizado
2019-03-15
·
CVE-2016-5637
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
libbpg versions 0.9.5 through 0.9.7
Description
The issue is related to a "type confusion" problem in the restore tqb pixels function, which mishandles the
transquant bypass enable flag value. This allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted BPG image.Recommendations
For libbpg versions 0.9.5 through 0.9.7, consider disabling the
restore tqb pixels function until a patch is available to prevent potential exploitation.Correção
RCE
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Libbpg