PT-2016-6610 · Bellard+1 · Libbpg+1
Puzzor
·
Published
2016-07-15
·
Updated
2019-03-15
·
CVE-2016-5637
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
libbpg versions 0.9.5 through 0.9.7
Description
The issue is related to a "type confusion" problem in the restore tqb pixels function, which mishandles the
transquant bypass enable flag value. This allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted BPG image.Recommendations
For libbpg versions 0.9.5 through 0.9.7, consider disabling the
restore tqb pixels function until a patch is available to prevent potential exploitation.Fix
RCE
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Libbpg