PT-2017-17621 · Potrace+1 · Potrace+1

Agostino Sarubbo

·

Published

2017-03-26

·

Updated

2017-08-19

·

CVE-2017-7263

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Potrace version 1.14
Description The issue is related to the bm readbody bmp function in bitmap io.c, which allows remote attackers to cause a denial of service, resulting in a heap-based buffer over-read and application crash, or possibly have other unspecified impacts via a crafted BMP image.
Recommendations For Potrace version 1.14, consider restricting the use of the bm readbody bmp function until a patch is available. As a temporary workaround, avoid processing crafted BMP images to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2085
CVE-2017-7263

Affected Products

Alt Linux
Potrace