CVE-2022-32323
published 2022-07-14CVE-2022-32323: AutoTrace v0.40.0 was discovered to contain a heap overflow via the ReadImage function at input-bmp.c:660.
PriorityP432high7.3CVSS 3.1
AVLACLPRNUIRSUCHIHAL
EPSS
0.88%
55.0th percentile
AutoTrace v0.40.0 was discovered to contain a heap overflow via the ReadImage function at input-bmp.c:660.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| autotrace_project | autotrace | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5j5g-gfrq-r5jc: AutoTrace v0
ghsa_unreviewed·2022-07-15
CVE-2022-32323 [CRITICAL] CWE-787 GHSA-5j5g-gfrq-r5jc: AutoTrace v0
AutoTrace v0.40.0 was discovered to contain a heap overflow via the ReadImage function at input-bmp.c:660.
OSV
CVE-2022-32323: AutoTrace v0
osv·2022-07-14·CVSS 7.3
CVE-2022-32323 [HIGH] CVE-2022-32323: AutoTrace v0
AutoTrace v0.40.0 was discovered to contain a heap overflow via the ReadImage function at input-bmp.c:660.
Red Hat
autotrace: heap-buffer overflow via the ReadImage() at input-bmp.c
vendor_redhat·2022-07-14·CVSS 7.3
CVE-2022-32323 [HIGH] CWE-119 autotrace: heap-buffer overflow via the ReadImage() at input-bmp.c
autotrace: heap-buffer overflow via the ReadImage() at input-bmp.c
AutoTrace v0.40.0 was discovered to contain a heap overflow via the ReadImage function at input-bmp.c:660.
A buffer overflow flaw was found in the autotrace package. This flaw allows an attacker to trick the user into opening a maliciously crafted BMP image, triggering arbitrary code execution or causing the application to crash.
Statement: The inkscape package distributed with Red Hat Enterprise Linux 9 is not affected by this issue. Although it ships autotrace as a bundled dependency, it does not include the affected BMP reader code.
Package: autotrace (Red Hat Enterprise Linux 6) - Out of support scope
Package: autotrace (Red Hat Enterprise Linux 7) - Out of support scope
Package: inkscape (Red Hat Enterprise Linux
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/autotrace/autotrace/commit/2b44c173027736c64b3f379bd154c41bab745423https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4CZVCQH4L7KC5GXLU6SCESXR5TGSKQ2H/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UKZPC4WCDOJ7BPJOMZ46AV27RCABZRYA/https://github.com/autotrace/autotrace/commit/2b44c173027736c64b3f379bd154c41bab745423https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4CZVCQH4L7KC5GXLU6SCESXR5TGSKQ2H/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UKZPC4WCDOJ7BPJOMZ46AV27RCABZRYA/
2022-07-14
Published