Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:32947
HistoryNov 13, 2021 - 12:40 a.m.

Integer Overflow

2021-11-1300:40:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
autotrace
integer overflow
input-bmp.c
malloc
bitmap image
system hang
vulnerability

EPSS

0.001

Percentile

38.6%

autotrace is vulnerable integer overflows. A biWidth*biBitCnt integer overflow in input-bmp.c allows attackers to provide an unexpected input value to malloc via a malformed bitmap image resulting in a system hang.