PT-2017-18748 · Autotrace+1 · Autotrace+1
Agostino Sarubbo
·
Published
2017-05-23
·
Updated
2024-07-04
·
CVE-2017-9166
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AutoTrace version 0.31.1
Description
The issue is related to a heap-based buffer over-read in the GET COLOR function, located in color.c. This occurs at line 18, column 11, of the libautotrace.a file in AutoTrace.
Recommendations
For AutoTrace version 0.31.1, at the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Autotrace