libvips
cpe:2.3:a:libvips:libvips:*:*:*:*:*:*:*, +1 more
- <= 8.18.0
A vulnerability in libvips versions through 8.18.0 on 32-bit systems allows the 'gifload' operation to miscalculate image dimensions, resulting in an integer overflow. This issue has been addressed in version 8.18.1.
The vulnerability can lead to a denial-of-service condition by causing a crash or unexpected behavior in applications that use libvips for image processing.
Users can update to libvips version 8.18.1 or later to address this vulnerability. Alternatively, the 'VipsForeignLoadNsgif' operation can be blocked using 'vips_operation_block_set', available in most language bindings.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.