Multiple integer overflows in CamlImages 2.2 and earlier might allow context-dependent attackers to execute arbitrary code via a crafted PNG image with large width and height values that trigger a heap-based buffer overflow in the (1) read_png_file or (2) read_png_file_as_rgb24 function.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade camlimagesUpgrade advi | Jul 30, 2024 | Jul 5, 2009 |
| Gentoo Linux | — | Upgrade dev-ml/camlimages. | Oct 30, 2017 | Jul 5, 2009 |
| Ubuntu | — | Upgrade adviUpgrade camlimages | Nov 19, 2024 | Jul 5, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub