UBUNTU-CVE-2017-7263
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-7263
Summary:
Details: The bm_readbody_bmp function in bitmap_io.c in Potrace 1.14 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted BMP image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8698.
References: https://ubuntu.com/security/CVE-2017-7263, https://blogs.gentoo.org/ago/2017/03/03/potrace-heap-based-buffer-overflow-in-bm_readbody_bmp-bitmap_io-c-incomplete-fix-for-cve-2016-8698/, http://seclists.org/oss-sec/2017/q1/682, https://www.cve.org/CVERecord?id=CVE-2017-7263
Affected packages
Package
Name: potrace
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
