Libbpg BGP image decoding Code... CVE-2016-8710 CNNVD-201702-168

6.8 AV AC AU C I A
发布: 2017-01-26
修订: 2022-12-13

### Summary An exploitable heap write out of bounds vulnerability exists in the decoding of BPG images in libbpg library. A crafted BPG image decoded by libbpg can cause an integer underflow vulnerability causing an out of bounds heap write leading to remote code execution. This vulnerability can be triggered via attempting to decode a crafted BPG image using libbpg. ### Tested Versions Libbpg - 0.9.4 and 0.9.7 ### Product URLs http://bellard.org/bpg/bpg_spec.txt ### CVSSv3 Score 7.5 - CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H ### Details BPG (Better Portable Graphics) is an image format created in 2014 based on the HECV video compression standard. BPG has been praised for its ability to produce the same quality image as JPEG or JPEG XR, but in a much smaller file size. It is currently in line to be incorporated in the multimedia player VLC. During the decoding of a BPG, in the `restore_tqb_pixels function`, an attacker controlled integer underflow can occur [1] during the...

0%
暂无可用Exp或PoC
当前有2条受影响产品信息