PT-2021-6807 · Libvips+3 · Libvips+3

Lqiulin

·

Published

2020-10-08

·

Updated

2023-10-18

·

CVE-2021-27847

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Libvips version 8.10.5
Description The issue is related to a Division-By-Zero vulnerability in the functions vips eye point and vips mask point of the Libvips library. This vulnerability is caused by the lack of a check for division by zero. An attacker can exploit this vulnerability to cause a denial of service.
Recommendations For Libvips version 8.10.5, consider disabling the vips eye point and vips mask point functions as a temporary workaround until a patch is available. Restrict access to the affected components eye.c and mask.c to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Divide By Zero

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2977
BDU:2022-02230
CVE-2021-27847
USN-6437-1

Affected Products

Alt Linux
Libvips
Linuxmint
Ubuntu