PT-2018-18177 · David Tschumperle · Cimg
Xiaoqx
·
Publicado
2018-03-02
·
Atualizado
2020-11-02
·
CVE-2018-7638
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CImg version 220
Description
A heap-based buffer over-read issue occurs in the load bmp function in CImg.h when loading a crafted bmp image, specifically in the "256 colors" case, also referred to as case 8.
Recommendations
For version 220, consider avoiding the use of the load bmp function in CImg.h until a patch is available, or refrain from loading crafted bmp images to minimize the risk of exploitation.
Exploit
Correção
Out of bounds Read
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cimg