CVE-2022-1325
Summary
| CVE | CVE-2022-1325 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-31 16:15:00 UTC |
| Updated | 2022-09-07 16:23:00 UTC |
| Description | A flaw was found in Clmg, where with the help of a maliciously crafted pandore or bmp file with modified dx and dy header field values it is possible to trick the application into allocating huge buffer sizes like 64 Gigabyte upon reading the file from disk or from a virtual buffer. |
Risk And Classification
Problem Types: CWE-770
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 2074549 – (CVE-2022-1325) CVE-2022-1325 CImg: Denial of service via RAM exhaustion in _load_bmp | MISC | bugzilla.redhat.com | |
| Denial of service via RAM exhaustion in _load_bmp · Issue #343 · GreycLab/CImg · GitHub | MISC | github.com | |
| CImg<>::load_bmp() and CImg<>::load_pandore(): Check that dimensions … · GreycLab/CImg@619cb58 · GitHub | MISC | github.com | |
| add global hardening against RAM exhaustions in safe_size by 7unn3l · Pull Request #348 · GreycLab/CImg · GitHub | MISC | github.com | |
| unchecked size in _load_bmp leads to RAM exhaustion in version 3.10 vulnerability found in cimg | MISC | huntr.dev | |
| Red Hat Customer Portal - Access to 24x7 support and knowledge | MISC | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 182019 Debian Security Update for cimg (CVE-2022-1325)