CVE-2017-9159
published 2017-05-23CVE-2017-9159: libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid write and SEGV), related to the pnm_load_rawpbm function in…
PriorityP434high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
2.00%
78.8th percentile
libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid write and SEGV), related to the pnm_load_rawpbm function in input-pnm.c:391:15.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| autotrace_project | autotrace | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
autotrace: Multiple security issues
vendor_redhat·2017-05-20·CVSS 7.5
CVE-2017-9159 [HIGH] autotrace: Multiple security issues
autotrace: Multiple security issues
libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid write and SEGV), related to the pnm_load_rawpbm function in input-pnm.c:391:15.
Statement: Red Hat Product Security has rated these issues as having Low security impact. These issues are not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: autotrace (Red Hat Enterprise Linux 6) - Will not fix
Package: autotrace (Red Hat Enterprise Linux 7) - Will not fix
GHSA
GHSA-776h-4xx9-fp28: libautotrace
ghsa_unreviewed·2022-05-17
CVE-2017-9159 [HIGH] CWE-787 GHSA-776h-4xx9-fp28: libautotrace
libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid write and SEGV), related to the pnm_load_rawpbm function in input-pnm.c:391:15.
OSV
CVE-2017-9159: libautotrace
osv·2017-05-23·CVSS 7.5
CVE-2017-9159 [HIGH] CVE-2017-9159: libautotrace
libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid write and SEGV), related to the pnm_load_rawpbm function in input-pnm.c:391:15.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-9151 CVE-2017-9152 CVE-2017-9153 CVE-2017-9154 CVE-2017-9155 CVE-2017-9156 CVE-2017-9157 CVE-2017-9158 CVE-2017-9159 CVE-2017-9160 CVE-2017-9161 ... autotrace: CVE-2017-9151..CVE-2017-9200 au
bugzilla·2017-05-23·CVSS 9.8
CVE-2017-9151 [CRITICAL] CVE-2017-9151 CVE-2017-9152 CVE-2017-9153 CVE-2017-9154 CVE-2017-9155 CVE-2017-9156 CVE-2017-9157 CVE-2017-9158 CVE-2017-9159 CVE-2017-9160 CVE-2017-9161 ... autotrace: CVE-2017-9151..CVE-2017-9200 au
CVE-2017-9151 CVE-2017-9152 CVE-2017-9153 CVE-2017-9154 CVE-2017-9155 CVE-2017-9156 CVE-2017-9157 CVE-2017-9158 CVE-2017-9159 CVE-2017-9160 CVE-2017-9161 ... autotrace: CVE-2017-9151..CVE-2017-9200 autotrace: Multiple security issues [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant t
Bugzilla
CVE-2017-9151..CVE-2017-9200 autotrace: Multiple security issues
bugzilla·2017-05-23·CVSS 9.8
CVE-2017-9151 [CRITICAL] CVE-2017-9151..CVE-2017-9200 autotrace: Multiple security issues
CVE-2017-9151..CVE-2017-9200 autotrace: Multiple security issues
Multiple vulnerabilities were found in autotrace.
CVE-2017-9200: libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-tga.c:528:63.
CVE-2017-9199: libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-tga.c:192:19.
CVE-2017-9198: libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-tga.c:508:18.
CVE-2017-9197: libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-tga.c:498:55.
CVE-2017-9196: libautotrace.a in AutoTrace 0.31.1 has a "negative-size-param" issue in the ReadImage function in input-tga.c:528:7.
CVE-2017-9195: libautotrace.a in AutoTrace 0.31.1 has a heap-based
2017-05-23
Published