PT-2023-27226 · Libvips+3 · Libvips+3
Christopher Krah
·
Published
2020-10-08
·
Updated
2025-04-21
·
CVE-2023-40032
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
libvips versions 8.14.3 or earlier
Description
A specially crafted SVG input can cause libvips to segfault when attempting to parse a malformed UTF-8 character. libvips is a demand-driven, horizontally threaded image processing library.
Recommendations
For libvips versions 8.14.3 or earlier, upgrade to libvips version 8.14.4 (or later) when processing untrusted input.
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Linuxmint
Ubuntu
Libvips