Lucene search

K
cvelistRedhatCVELIST:CVE-2020-25693
HistoryDec 03, 2020 - 4:48 p.m.

CVE-2020-25693

2020-12-0316:48:26
CWE-190
redhat
www.cve.org
5
cimg
integer overflows
heap buffer overflows
load_pnm
specially crafted input file
application availability
data integrity

AI Score

7.9

Confidence

High

EPSS

0.003

Percentile

69.4%

A flaw was found in CImg in versions prior to 2.9.3. Integer overflows leading to heap buffer overflows in load_pnm() can be triggered by a specially crafted input file processed by CImg, which can lead to an impact to application availability or data integrity.

CNA Affected

[
  {
    "product": "CImg",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "CImg versions before 2.9.3"
      }
    ]
  }
]

AI Score

7.9

Confidence

High

EPSS

0.003

Percentile

69.4%