SB2017041011 - Multiple vulnerabilities in ImageWorsener
Published: April 10, 2017 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Out-of-bounds read (CVE-ID: CVE-2017-7623)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in The iwmiffr_convert_row32 function in imagew-miff.c in libimageworsener.a in ImageWorsener 1.3.0. A remote attacker can perform a denial of service (heap-based buffer over-read) via a crafted file.
2) Input validation error (CVE-ID: CVE-2017-7624)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The iw_read_bmp_file function in imagew-bmp.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to consume an amount of available memory via a crafted file.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.