PT-2026-36892 · Unknown · Cimg Library
Jorgebarredo14
·
Published
2026-05-04
·
Updated
2026-05-04
·
CVE-2026-42144
CVSS v3.1
6.1
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
CImg Library versions prior to commit 4ca26bc
Description
An integer overflow exists in the
load pnm() function during the computation of WHD size. A specially crafted PNM, PGM, or PPM file containing large dimension values can cause the calculation to wrap around, bypassing the memory allocation guard. This results in the allocation of an undersized buffer, which may lead to a heap buffer overflow when processing untrusted image files.Recommendations
Update CImg Library to the version containing commit 4ca26bc.
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cimg Library