BlackBerry QNX Software Development Platform
cpe:2.3:a:blackberry:qnx_software_development_platform:*:*:*:*:*:*:*
- 8.0
- 7.1
- 7.0
An out-of-bounds read vulnerability has been identified in the TIFF image codec of QNX Software Development Platform (SDP) versions 8.0, 7.1, and 7.0. This vulnerability could allow an unauthenticated attacker to cause information disclosure in the context of the process using the image codec, by inducing the system to parse a maliciously crafted TIFF image file.
Exploitation of this vulnerability could lead to unauthorized information disclosure within the process that is using the affected image codec.
Users are advised to update to the latest version of the QNX image codecs. These updates are available through the QNX Software Center. QNX SDP 8.0 users should update to version 0.0.1.00077T202410011913L, QNX SDP 7.1 users should update to version 0.0.7.00759T202410010845L, and QNX SDP 7.0 users should update to version 7.0.7094.L202410281606.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.