PT-2015-7945 · Potrace · Potrace

Published

2015-12-16

·

Updated

2015-12-16

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Potrace versions prior to 1.13
Description The issue is related to critical bugs in the processing of BMP files, which can cause the program to crash or potentially be exploited in other ways by feeding it specially crafted BMP files. The bugs are due to heap overflow, null pointer dereference, and divide by zero issues.
Recommendations For versions prior to 1.13, update to version 1.13 or later to resolve the issue. As a temporary workaround, consider avoiding the use of specially crafted BMP files that could trigger the heap overflow, null pointer dereference, or divide by zero issues until a patch is available.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

MGASA-2015-0474

Affected Products

Potrace