libvips
cpe:2.3:a:libvips:libvips:*:*:*:*:*:*:*, +1 more
- <= 8.18.0
A heap-based buffer overflow vulnerability has been identified in libvips versions through 8.18.0. The issue arises in the 'vipsload' operation, where incorrect determination of image dimensions can lead to an integer overflow, allowing for a buffer overflow on the heap.
Exploitation of this vulnerability can lead to a heap-based buffer overflow, which may allow for arbitrary code execution or cause a program crash.
Users can upgrade to libvips version 8.18.1 or later to address this vulnerability. For those unable to upgrade, it is possible to block the 'VipsForeignLoadVips' operation using 'vips_operation_block_set', available in most language bindings. Alternatively, the 'VIPS_BLOCK_UNTRUSTED' environment variable can be set to disable all 'untrusted' image decoders.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.