Heap-based buffer overflow in the pstoedit_suffix_table_init function in output-pstoedit.c in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted bmp image file.
CVSS Details
- CVSS 3.0 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade autotraceUpgrade autotrace-debuginfoUpgrade autotrace-devel | Feb 7, 2023 | Feb 15, 2017 |
| Debian | — | Upgrade autotrace | Mar 31, 2017 | Sep 15, 2016 |
| Gentoo Linux | — | Upgrade media-gfx/autotrace. | Oct 30, 2017 | Feb 15, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 10, 2016 |
| Ubuntu | — | Upgrade autotrace | Nov 19, 2024 | Feb 15, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub