PT-2016-6610 · Bellard+1 · Libbpg+1

Puzzor

·

Published

2016-07-15

·

Updated

2019-03-15

·

CVE-2016-5637

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libbpg versions 0.9.5 through 0.9.7
Description The issue is related to a "type confusion" problem in the restore tqb pixels function, which mishandles the transquant bypass enable flag value. This allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted BPG image.
Recommendations For libbpg versions 0.9.5 through 0.9.7, consider disabling the restore tqb pixels function until a patch is available to prevent potential exploitation.

Fix

RCE

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1439
CVE-2016-5637

Affected Products

Alt Linux
Libbpg