BlackBerry QNX Software Development Platform
cpe:2.3:a:blackberry:qnx_software_development_platform:*:*:*:*:*:*:*
- 8.0
- 7.1
- 7.0
An off-by-one error vulnerability has been identified in the TIFF image codec of QNX Software Development Platform (SDP) versions 8.0, 7.1, and 7.0. This vulnerability could allow an unauthenticated attacker to cause information disclosure within the context of the process using the image codec. The issue arises when the system is induced to parse a maliciously crafted TIFF image file.
Exploitation of this vulnerability could lead to unauthorized information disclosure in the context of the process using the image codec.
QNX has released updates for the affected versions that address this vulnerability. These updates are available through the QNX Software Center. QNX recommends that all affected customers update their QNX-based products at their earliest convenience.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.