PT-2024-4484 · Blackberry · Qnx Sdp
Published
2024-05-13
·
Updated
2025-12-01
·
CVE-2024-35213
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
QNX SDP versions 6.6, 7.0, and 7.1
Description
The issue is related to an improper input validation vulnerability in the SGI Image Codec. This could allow an attacker to potentially cause a denial-of-service condition or execute code in the context of the image processing process by loading specially crafted SGI files. The vulnerability has been reportedly exploited in the wild.
Recommendations
For QNX SDP version 6.6, update to a fixed version when available.
For QNX SDP version 7.0, update to a fixed version when available.
For QNX SDP version 7.1, update to a fixed version when available.
As a temporary workaround, consider restricting the use of the SGI Image Codec until a patch is available.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Qnx Sdp