libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applications that define unusual custom libvips sources and use them to process untrusted uncompressed PPM i…
提示
摘要
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applications that define unusual custom libvips sources and use them to process untrusted uncompressed PPM images can trigger a max/min error in vips_source_read_to_memory in libvips/iofuncs/source.c. The function uses VIPS_MAX instead of VIPS_MIN when selecting the remaining read size, allowing up to 4032 bytes to be written beyond the allocated heap buffer and causing memory corruption or a process cras…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://github.com/libvips/libvips/commit/80e021c6cdda0f80b756c2109d99839c94c03258
- https://github.com/libvips/libvips/pull/5038
- https://github.com/libvips/libvips/releases/tag/v8.18.3
- https://github.com/libvips/libvips/security/advisories/GHSA-rjmm-3qch-m9rg
时间线
- nvd_ingest NVD