CVE-2023-40032
CVSS V2 None
CVSS V3 None
Description
libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libvips versions 8.14.3 or earlier to segfault when attempting to parse a malformed UTF-8 character. Users should upgrade to libvips version 8.14.4 (or later) when processing untrusted input.
Overview
- CVE ID
- CVE-2023-40032
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-09-11T18:34:59.025Z
- Last Modified Date
- 2023-09-11T18:34:59.025Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/libvips/libvips/security/advisories/GHSA-33qp-9pq7-9584 | x_refsource_CONFIRM |
https://github.com/libvips/libvips/pull/3604 | x_refsource_MISC |
https://github.com/libvips/libvips/commit/e091d65835966ef56d53a4105a7362cafdb1582b | x_refsource_MISC |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YU2FFC47X2XDEGEHEWAGLU5L3R6FEYD2/ |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-40032 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-40032 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-25 02:28:25 | Added to TrackCVE |