PT-2020-5732 · David Tschumperle · Cimg

Published

2020-10-22

·

Updated

2021-05-05

·

CVE-2020-25693

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions: CImg versions prior to 2.9.3
Description: A flaw in CImg can be triggered by a specially crafted input file, leading to integer overflows and heap buffer overflows in the load pnm() function. This can impact application availability or data integrity. The issue can be exploited by a remote attacker using a specially crafted file, potentially affecting the confidentiality, integrity, and availability of protected information.
Recommendations: For versions prior to 2.9.3, update to version 2.9.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the load pnm() function until a patch is available. Avoid using specially crafted input files that could trigger the integer overflows and heap buffer overflows.

Exploit

Fix

Integer Overflow

Heap Based Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01646
CVE-2020-25693
DLA-2462-1
MGASA-2020-0443

Affected Products

Cimg