UBUNTU-CVE-2023-40032
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-40032
UBUNTU-CVE-2023-40032
Summary:
Details: libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libvips versions 8.14.3 or earlier to segfault when attempting to parse a malformed UTF-8 character. Users should upgrade to libvips version 8.14.4 (or later) when processing untrusted input.
References: https://ubuntu.com/security/CVE-2023-40032, https://github.com/libvips/libvips/pull/3604, https://github.com/libvips/libvips/commit/e091d65835966ef56d53a4105a7362cafdb1582b, https://github.com/libvips/libvips/security/advisories/GHSA-33qp-9pq7-9584, https://ubuntu.com/security/notices/USN-6437-1, https://www.cve.org/CVERecord?id=CVE-2023-40032
Affected packages
Package
Name: vips
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/jammy
Affected ranges
Type: ECOSYSTEM
Events:
