libvips
cpe:2.3:a:libvips:libvips:*:*:*:*:*:*:*, +1 more
- <= 8.18.1
A null pointer dereference vulnerability has been identified in the EXIF decoder of libvips, a fast image processing library, in versions prior to and including 8.18.1. The vulnerability arises because the decoder did not properly validate the range of EXIF tag groups before sending the data to libexif, potentially leading to a crash.
Exploitation of this vulnerability can cause a null pointer dereference, resulting in a crash of the application.
Users are advised to upgrade to libvips version 8.18.2 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.