Search CVE reports
1 – 3 of 3 results
Some fixes available 5 of 60
tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a “Negative-size-param”...
17 affected packages
blender, chromium-browser, gdal, insighttoolkit4, ivtools...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
blender | Not affected | Not affected | Not affected | Not affected |
chromium-browser | Not affected | Not affected | Not affected | Not affected |
gdal | Not affected | Not affected | Not affected | Not affected |
insighttoolkit4 | Not in release | Not affected | Not affected | Not affected |
ivtools | Not affected | Not affected | Not affected | Not affected |
libtk-img | Not affected | Not affected | Not affected | Not affected |
neuron | Not affected | Needs evaluation | Needs evaluation | Needs evaluation |
openjpeg2 | Not affected | Not affected | Not affected | Not affected |
paraview | Not affected | Not affected | Not affected | Not affected |
povray | Not affected | Not affected | Not affected | Not affected |
qt4-x11 | Not in release | Not in release | Not in release | Not affected |
qtimageformats-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
sfftobmp | Not affected | Not affected | Not affected | Not affected |
texmaker | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
tiff | Not affected | Not affected | Not affected | Fixed |
xloadimage | Not affected | Not affected | Not affected | Not affected |
Multiple vulnerabilities in xli before 1.17 may allow remote attackers to execute arbitrary code via “buffer management errors” from certain image properties, some of which may be related to integer overflows in PPM files.
2 affected packages
xli, xloadimage
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
xli | — | — | — | — |
xloadimage | — | — | — | — |
xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly quoted when calling the gunzip command.
2 affected packages
xli, xloadimage
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
xli | — | — | — | — |
xloadimage | — | — | — | — |