Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

7Unn3L

#45727of 53,630
5.5Total CVSS
Vulnerabilities · 1
PT-2022-13799
5.5
2022-08-31
Clmg · Clmg · CVE-2022-1325
**Name of the Vulnerable Software and Affected Versions** Clmg (affected versions not specified) **Description** A flaw in Clmg allows an attacker to trick the application into allocating huge buffer sizes, such as 64 Gigabyte, by using a maliciously crafted pandore or bmp file with modified `dx` and `dy` header field values. This can occur when the application reads the file from disk or from a virtual buffer. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.