QNX SDP PCX Image Codec Out-of-Bounds Write Vulnerability Allowing Code Execution or Denial-of-Service

Vulnerability

An out-of-bounds write vulnerability has been identified in the PCX image codec of QNX Software Development Platform (SDP) versions 8.0, 7.1, and 7.0. This vulnerability could allow an unauthenticated attacker to cause a denial-of-service condition or execute code in the context of the process using the image codec. The vulnerability arises when the image codec is induced to parse a maliciously crafted PCX format image file.

Impact

Exploitation of this vulnerability could lead to a denial-of-service condition or allow for remote code execution in the context of the process using the image codec.

Remediation

QNX has released updates for the affected PCX image codec in QNX SDP versions 8.0, 7.1, and 7.0. These updates are available through the QNX Software Center. QNX recommends that all affected customers update their QNX-based products at their earliest convenience.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
7.5
exploitability
4.7
remediation
8.3
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.